CVE-2014-2925: XSS
Cross-site scripting (XSS) vulnerability in AdvancedWirelessContent.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote attackers to inject arbitrary web script or HTML via the currentpage parameter to apply.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2925?
CVE-2014-2925 is classified as a moderate severity Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2014-2925?
To fix CVE-2014-2925, users should upgrade their router firmware to version 3.0.0.4.374.5047 or later.
Who is affected by CVE-2014-2925?
CVE-2014-2925 affects ASUS RT-AC68U and other RT series routers running firmware versions prior to 3.0.0.4.374.5047.
What type of vulnerability is CVE-2014-2925?
CVE-2014-2925 is a Cross-site Scripting (XSS) vulnerability that allows attackers to inject web scripts or HTML.
How can attackers exploit CVE-2014-2925?
Attackers can exploit CVE-2014-2925 by manipulating the current_page parameter in apply.cgi to inject malicious scripts.