CVE-2021-3186: XSS
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47multi allows remote attackers to inject arbitrary web script or HTML via the Wifi Name parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update Wifi Name to a value that does not include HTML or script content (e.g., remove/escape any injected web script or HTML) to mitigate the Stored XSS via the Wifi Name parameter on /main.html.
Tenda AC5 AC1200 (/main.html Wifi Settings) Wifi Name parameter = Sanitize/validate input to prevent HTML/script injection
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3186?
CVE-2021-3186 is classified as a medium severity vulnerability due to its potential for remote exploitation via stored XSS.
How do I fix CVE-2021-3186?
To fix CVE-2021-3186, update the Tenda AC5 AC1200 firmware to a version that resolves this vulnerability.
What type of vulnerability is CVE-2021-3186?
CVE-2021-3186 is a Stored Cross-site Scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
What impact does CVE-2021-3186 have on users?
CVE-2021-3186 could allow attackers to execute arbitrary web scripts in the context of the user's session.
Who is affected by CVE-2021-3186?
CVE-2021-3186 affects users of the Tenda AC5 AC1200 router running firmware version V15.03.06.47_multi.