CVE-2018-14710: XSS
Published May 13, 2019
·Updated
Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter.
Affected Software
2 affected components
ASUS Rt-ac3200 Firmware=3.0.0.4.382.50010
ASUS RT-AC3200
Event History
May 13, 2019
CVE Published
via MITRE·12:19 PM
Data Sourced
via MITRE·12:19 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-14710.
2
What is the severity of CVE-2018-14710?
The severity of CVE-2018-14710 is medium.
3
What is the description of CVE-2018-14710?
CVE-2018-14710 is a vulnerability that allows attackers to execute JavaScript via the 'hook' URL parameter in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010.
4
How can attackers exploit CVE-2018-14710?
Attackers can exploit CVE-2018-14710 by injecting malicious JavaScript code through the 'hook' URL parameter in the appGet.cgi script.
5
Is there a fix available for CVE-2018-14710?
There is no information available on a fix for CVE-2018-14710 at this time.