First published: Fri Aug 03 2018(Updated: )
Tenda D152 ADSL routers allow XSS via a crafted SSID.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tendacn D152 | ||
Tendacn D152 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14497 is categorized as a medium severity vulnerability.
To mitigate CVE-2018-14497, update the firmware of the Tenda D152 router to the latest version provided by the manufacturer.
CVE-2018-14497 is a cross-site scripting (XSS) vulnerability that can be exploited through a crafted SSID.
CVE-2018-14497 specifically affects Tenda D152 ADSL routers with the vulnerable firmware versions.
Yes, if exploited, CVE-2018-14497 can potentially allow attackers to steal session cookies through XSS.