PT-2022-1940 · NetGear · Netgear Wac120 Ac Access Point
Published
2022-01-18
·
Updated
2022-03-11
·
CVE-2021-46382
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Netgear WAC120 AC Access Point (affected versions not specified)
Description
The issue is related to unauthenticated cross-site scripting (XSS) in the Netgear WAC120 AC Access Point, which may lead to multiple attacks, including session hijacking and clipboard hijacking. This is due to the lack of protection measures for the web page structure, allowing a remote attacker to conduct cross-site scripting attacks.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netgear Wac120 Ac Access Point