First published: Tue Feb 08 2022(Updated: )
Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on the adjacent network to inject an arbitrary script via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-300febk-r Firmware | <1.16 | |
Elecom Wrc-300febk-r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21799 is a cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier versions.
The severity of CVE-2022-21799 is medium, with a CVSS score of 5.2.
CVE-2022-21799 allows an attacker on the adjacent network to inject an arbitrary script via unspecified vectors in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier versions.
To fix the cross-site scripting vulnerability, update ELECOM LAN router WRC-300FEBK-R firmware to version 1.16 or later.
You can find more information about CVE-2022-21799 at the following references: 1. [JVN](https://jvn.jp/en/jp/JVN17482543/index.html) 2. [Elecom Security Advisory](https://www.elecom.co.jp/news/security/20220208-02/)