CVE-2015-1437: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Asus RT-N10+ D1 router with firmware 2.1.1.1.70 allow remote attackers to inject arbitrary web script or HTML via the flag parameter to (1) resultofgetchangedstatus.asp or (2) errorpage.htm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1437?
CVE-2015-1437 is classified as a medium severity vulnerability due to its ability to allow remote attackers to execute scripts on affected devices.
How do I fix CVE-2015-1437?
To mitigate CVE-2015-1437, it is recommended to update the Asus RT-N10+ D1 router firmware to the latest version beyond 2.1.1.1.70.
Which devices are affected by CVE-2015-1437?
CVE-2015-1437 affects the Asus RT-N10+ D1 router running firmware version 2.1.1.1.70.
What types of attacks are possible due to CVE-2015-1437?
CVE-2015-1437 allows for cross-site scripting (XSS) attacks, enabling attackers to inject malicious scripts via specific parameters.
Can CVE-2015-1437 be exploited remotely?
Yes, CVE-2015-1437 can be exploited remotely by attackers through the vulnerable web interfaces.