PT-2022-1940 · NetGear · Netgear Wac120 Ac Access Point

Published

2022-01-18

·

Updated

2022-03-11

·

CVE-2021-46382

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Netgear WAC120 AC Access Point (affected versions not specified)
Description The issue is related to unauthenticated cross-site scripting (XSS) in the Netgear WAC120 AC Access Point, which may lead to multiple attacks, including session hijacking and clipboard hijacking. This is due to the lack of protection measures for the web page structure, allowing a remote attacker to conduct cross-site scripting attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01488
CVE-2021-46382

Affected Products

Netgear Wac120 Ac Access Point