First published: Thu Apr 29 2021(Updated: )
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mercusys Mercury X18g Firmware | =1.0.5 | |
MERCUSYS Mercury X18G |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25810 is a Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices.
CVE-2021-25810 allows attackers to exploit a Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices by sending crafted values to certain parameters.
The severity of CVE-2021-25810 is medium, with a severity score of 6.1.
To fix CVE-2021-25810, it is recommended to update your MERCUSYS Mercury X18G firmware to a version that addresses the Cross site Scripting (XSS) vulnerability.
You can find more information about CVE-2021-25810 in the references provided: [GitHub link](https://github.com/pokerfacett/MY_REQUEST/blob/master/Mercury%20Router%20X18g%20v1.0.5%20Stored%20XSS.md), [MERCUSYS website](https://www.mercurycom.com.cn/product-521-1.html), [Mercusys website](https://www.mercusys.com/en/)