First published: Mon May 13 2019(Updated: )
Cross-site scripting in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute JavaScript via the "hook" URL parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ac3200 Firmware | =3.0.0.4.382.50010 | |
ASUS RT-AC3200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-14710.
The severity of CVE-2018-14710 is medium.
CVE-2018-14710 is a vulnerability that allows attackers to execute JavaScript via the 'hook' URL parameter in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010.
Attackers can exploit CVE-2018-14710 by injecting malicious JavaScript code through the 'hook' URL parameter in the appGet.cgi script.
There is no information available on a fix for CVE-2018-14710 at this time.