CVE-2018-17021: XSS
Published Sep 13, 2018
·Updated
Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.38432738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter.
Affected Software
2 affected components
ASUS Gt-ac5300 Firmware<=3.0.0.4.384_32738
ASUS GT-AC5300
Event History
Sep 13, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-17021?
CVE-2018-17021 is a cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738.
2
How does CVE-2018-17021 affect ASUS GT-AC5300 devices?
CVE-2018-17021 allows remote attackers to inject arbitrary web scripts or HTML via the appGet.cgi hook parameter.
3
What is the severity of CVE-2018-17021?
CVE-2018-17021 is categorized as medium severity with a CVSS score of 6.1.
4
Is ASUS GT-AC5300 firmware vulnerable to CVE-2018-17021?
ASUS GT-AC5300 firmware version up to and including 3.0.0.4.384_32738 is vulnerable to CVE-2018-17021.
5
How can I fix CVE-2018-17021 on my ASUS GT-AC5300 device?
To fix CVE-2018-17021, update your ASUS GT-AC5300 device firmware to a version that is not affected by the vulnerability.