First published: Tue Nov 27 2018(Updated: )
Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a modified URL path.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mi Miwifi OS | =2.22.15 | |
Mi Router 3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13022 is classified as a Cross-site Scripting (XSS) vulnerability which can pose a significant risk to web security.
To fix CVE-2018-13022, users should update the Xiaomi Mi Router 3 firmware to the latest version that addresses this vulnerability.
CVE-2018-13022 can be exploited to execute arbitrary JavaScript, potentially leading to session hijacking or data theft.
CVE-2018-13022 specifically affects Xiaomi Mi Router 3 running the firmware version 2.22.15.
If you suspect exploitation of CVE-2018-13022, it is recommended to immediately update the device's firmware and monitor network traffic for suspicious activity.