CVE-2020-5606: XSS
Published Sep 18, 2020
·Updated
Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page.
Affected Software
2 affected components
Buffalo Airstation Whr-g54s Firmware<=1.43
Buffalo Airstation Whr-g54s
Event History
Sep 18, 2020
CVE Published
via MITRE·05:05 AM
Data Sourced
via MITRE·05:05 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-5606?
CVE-2020-5606 is a cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier that allows remote attackers to inject arbitrary script via a specially crafted page.
2
What is the severity of CVE-2020-5606?
CVE-2020-5606 has a severity rating of 6.1 (medium).
3
How can remote attackers exploit CVE-2020-5606?
Remote attackers can exploit CVE-2020-5606 by injecting arbitrary script via a specially crafted page.
4
Is Buffalo Airstation Whr-g54s firmware vulnerable to CVE-2020-5606?
Yes, Buffalo Airstation Whr-g54s firmware versions 1.43 and earlier are vulnerable to CVE-2020-5606.
5
How do I fix CVE-2020-5606?
To fix CVE-2020-5606, update the WHR-G54S firmware to a version later than 1.43.