First published: Mon Apr 21 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the current_page parameter to apply.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ASUS TM-AC1900 | =3.0.0.4.376_3169 | |
ASUS RT-AC68R | <=3.0.0.4.374_4983 | |
ASUS RT-AC68R | =3.0.0.4.374.4755 | |
ASUS RT-AC68R | =3.0.0.4.374_4887 | |
ASUS RT-AC68R |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2925 is classified as a moderate severity Cross-site Scripting (XSS) vulnerability.
To fix CVE-2014-2925, users should upgrade their router firmware to version 3.0.0.4.374.5047 or later.
CVE-2014-2925 affects ASUS RT-AC68U and other RT series routers running firmware versions prior to 3.0.0.4.374.5047.
CVE-2014-2925 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject web scripts or HTML.
Attackers can exploit CVE-2014-2925 by manipulating the current_page parameter in apply.cgi to inject malicious scripts.