CVE-2021-44148
07.12.2021, 22:15
GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.
Vendor | Product | Version |
---|---|---|
gl-inet | gl-ar150_firmware | 2.0 ≤ 𝑥 < 3.0 |
𝑥
= Vulnerable software versions