CVE-2018-14497: XSS
Published Aug 3, 2018
·Updated
Tenda D152 ADSL routers allow XSS via a crafted SSID.
Affected Software
2 affected components
Tendacn D152 Firmware
Tendacn D152
Event History
Aug 3, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14497?
CVE-2018-14497 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2018-14497?
To mitigate CVE-2018-14497, update the firmware of the Tenda D152 router to the latest version provided by the manufacturer.
3
What type of vulnerability is CVE-2018-14497?
CVE-2018-14497 is a cross-site scripting (XSS) vulnerability that can be exploited through a crafted SSID.
4
Which devices are affected by CVE-2018-14497?
CVE-2018-14497 specifically affects Tenda D152 ADSL routers with the vulnerable firmware versions.
5
Can CVE-2018-14497 allow attackers to steal session cookies?
Yes, if exploited, CVE-2018-14497 can potentially allow attackers to steal session cookies through XSS.