First published: Mon Jan 04 2021(Updated: )
In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | <=2021-01-04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3014 is a vulnerability in MikroTik RouterOS that allows for reflected XSS via the target parameter on the hotspot login page.
CVE-2021-3014 has a severity rating of 6.1, which is considered medium.
The affected software is MikroTik RouterOS versions up to and including 2021-01-04.
To fix CVE-2021-3014, it is recommended to update to a version of MikroTik RouterOS that is after 2021-01-04.
The CWE for CVE-2021-3014 is CWE-79, which is Cross-Site Scripting (XSS).