First published: Fri Apr 22 2022(Updated: )
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Asus Rt-ax88u Firmware | <3.0.0.4.386.46065 | |
ASUS RT-AX88U |
Update RT-AX88U firmware version to 3.0.0.4.386.46065
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this ASUS RT-AX88U vulnerability is CVE-2022-26673.
The severity of CVE-2022-26673 is medium with a severity value of 5.4.
The ASUS RT-AX88U firmware up to version 3.0.0.4.386.46065 is affected by CVE-2022-26673.
An attacker with general user privilege can exploit CVE-2022-26673 to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
Yes, the ASUS RT-AX88U is vulnerable to CVE-2022-26673.