CVE-2022-26673: ASUS RT-AX88U - Stored XSS
Published Apr 22, 2022
·Updated
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
Affected Software
2 affected components
ASUS Rt-ax88u Firmware<3.0.0.4.386.46065
ASUS RT-AX88U
Remediation
Information
Update RT-AX88U firmware version to 3.0.0.4.386.46065
Event History
Apr 22, 2022
CVE Published
via MITRE·06:50 AM
Data Sourced
via MITRE·06:50 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this ASUS RT-AX88U vulnerability?
The vulnerability ID of this ASUS RT-AX88U vulnerability is CVE-2022-26673.
2
What is the severity of CVE-2022-26673?
The severity of CVE-2022-26673 is medium with a severity value of 5.4.
3
What software is affected by CVE-2022-26673?
The ASUS RT-AX88U firmware up to version 3.0.0.4.386.46065 is affected by CVE-2022-26673.
4
How can an attacker exploit CVE-2022-26673?
An attacker with general user privilege can exploit CVE-2022-26673 to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
5
Is the ASUS RT-AX88U vulnerable to CVE-2022-26673?
Yes, the ASUS RT-AX88U is vulnerable to CVE-2022-26673.