CVE-2015-2681: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) nextpage, (2) groupid, (3) actionscript, or (4) flag parameter to startapply.htm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2681?
CVE-2015-2681 is considered to be a moderate severity vulnerability due to the potential for remote code execution via XSS.
How do I fix CVE-2015-2681?
To fix CVE-2015-2681, users should update the ASUS RT-G32 router firmware to a version that is not affected by this vulnerability.
What causes CVE-2015-2681?
CVE-2015-2681 is caused by improper sanitization of user input in multiple parameters, allowing for cross-site scripting attacks.
Who is affected by CVE-2015-2681?
Users of ASUS RT-G32 routers running firmware versions 2.0.2.6 and 2.0.3.2 are affected by CVE-2015-2681.
Can CVE-2015-2681 be exploited remotely?
Yes, CVE-2015-2681 can be exploited remotely by attackers targeting the affected ASUS RT-G32 router firmware.