First published: Sun Jan 24 2021(Updated: )
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda AC1200 Firmware | =15.03.06.47_multi | |
Tenda AC1200 V-W15Ev2 | =ac5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3186 is classified as a medium severity vulnerability due to its potential for remote exploitation via stored XSS.
To fix CVE-2021-3186, update the Tenda AC5 AC1200 firmware to a version that resolves this vulnerability.
CVE-2021-3186 is a Stored Cross-site Scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
CVE-2021-3186 could allow attackers to execute arbitrary web scripts in the context of the user's session.
CVE-2021-3186 affects users of the Tenda AC5 AC1200 router running firmware version V15.03.06.47_multi.