PT-2021-7936 · Openwrt · Openwrt Luci
Published
2021-05-25
·
Updated
2023-05-24
·
CVE-2021-33425
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenWrt LuCI version 19.07
Description
The issue is related to a stored cross-site scripting (XSS) vulnerability in the web interface of OpenWrt LuCI. This vulnerability allows attackers to inject arbitrary Javascript code into the OpenWrt Hostname via the Hostname Change operation, potentially enabling remote attackers to perform cross-site scripting attacks.
Recommendations
For OpenWrt LuCI version 19.07, consider disabling the Hostname Change operation until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the web interface to minimize the risk of exploitation. Avoid using the Hostname Change operation in the affected web interface until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openwrt Luci