First published: Thu Sep 13 2018(Updated: )
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Gt-ac5300 Firmware | <=3.0.0.4.384_32738 | |
ASUS GT-AC5300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17021 is a cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738.
CVE-2018-17021 allows remote attackers to inject arbitrary web scripts or HTML via the appGet.cgi hook parameter.
CVE-2018-17021 is categorized as medium severity with a CVSS score of 6.1.
ASUS GT-AC5300 firmware version up to and including 3.0.0.4.384_32738 is vulnerable to CVE-2018-17021.
To fix CVE-2018-17021, update your ASUS GT-AC5300 device firmware to a version that is not affected by the vulnerability.