CVE-2018-13022: XSS
Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a modified URL path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13022?
CVE-2018-13022 is classified as a Cross-site Scripting (XSS) vulnerability which can pose a significant risk to web security.
How do I fix CVE-2018-13022?
To fix CVE-2018-13022, users should update the Xiaomi Mi Router 3 firmware to the latest version that addresses this vulnerability.
What types of attacks can exploit CVE-2018-13022?
CVE-2018-13022 can be exploited to execute arbitrary JavaScript, potentially leading to session hijacking or data theft.
Which devices are affected by CVE-2018-13022?
CVE-2018-13022 specifically affects Xiaomi Mi Router 3 running the firmware version 2.22.15.
What actions should I take if I suspect exploitation of CVE-2018-13022?
If you suspect exploitation of CVE-2018-13022, it is recommended to immediately update the device's firmware and monitor network traffic for suspicious activity.