CVE-2020-23617: XSS
Published May 2, 2022
·Updated
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
Affected Software
4 affected components
TOTOLINK N200re Firmware=2.0
TOTOLINK N200RE
TOTOLINK N100re Firmware=2.0
TOTOLINK N100RE
Event History
May 2, 2022
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23617?
The severity of CVE-2020-23617 is medium with a CVSS score of 6.1.
2
What is the affected software of CVE-2020-23617?
The affected software of CVE-2020-23617 includes Totolink N200RE Firmware 2.0 and Totolink N100RE Firmware 2.0.
3
How can an attacker exploit CVE-2020-23617?
An attacker can exploit CVE-2020-23617 by executing arbitrary web scripts or HTML via the SCRIPT element on the error page of Totolink N200RE and N100RE Routers 2.0.
4
Is Totolink N200RE vulnerable to CVE-2020-23617?
No, Totolink N200RE is not vulnerable to CVE-2020-23617.
5
Is Totolink N100RE vulnerable to CVE-2020-23617?
No, Totolink N100RE is not vulnerable to CVE-2020-23617.