CVE-2020-7997: XSS
Published Jan 28, 2020
·Updated
ASUS WRT-AC66U 3 RT 3.0.0.4.37267 devices allow XSS via the Client Name field to the Parental Control feature.
Affected Software
4 affected components
ASUS Rt-ac66u Firmware=3.0.0.4.372_67
ASUS RT-AC66U
All of the following
ASUS Rt-ac66u Firmware=3.0.0.4.372_67
ASUS RT-AC66U
Event History
Jan 28, 2020
CVE Published
via MITRE·04:33 AM
Data Sourced
via MITRE·04:33 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7997?
The severity of CVE-2020-7997 is medium with a CVSS score of 6.1.
2
How does CVE-2020-7997 allow XSS attacks?
CVE-2020-7997 allows XSS attacks through the Client Name field of the Parental Control feature in ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices.
3
Which devices are affected by CVE-2020-7997?
ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices are affected by CVE-2020-7997.
4
How can I fix the XSS vulnerability in ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices?
To fix the XSS vulnerability in ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices, it is recommended to update the firmware to the latest version provided by the vendor.
5
Where can I find more information about CVE-2020-7997?
More information about CVE-2020-7997 can be found at the following reference: https://gist.github.com/adeshkolte/983bcadd82cc1fd60333098eb646ef68