First published: Fri Apr 28 2017(Updated: )
Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Iodata WN-AX1167GR Firmware | <=1.04 | |
Iodata WN-AC1167GR Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2148 is classified as a cross-site scripting vulnerability, which poses a medium to high severity risk depending on the exploit context.
To mitigate CVE-2017-2148, upgrade the WN-AC1167GR firmware to version 1.05 or later.
CVE-2017-2148 can be exploited by authenticated remote attackers via injected web scripts or HTML into the firmware interface.
Users of WN-AC1167GR firmware version 1.04 and earlier are affected by CVE-2017-2148.
While the best solution is to upgrade the firmware, users can limit access to the device's management interface to mitigate risks associated with CVE-2017-2148.