vendor:
TL-MR3220
by:
Thiago 'THX' Sena
6,1
CVSS
MEDIUM
Cross-site scripting (XSS)
79
CWE
Product Name: TL-MR3220
Affected Version From: TL-MR3220
Affected Version To: TL-MR3220
Patch Exists: YES
Related CWE: CVE-2017-15291
CPE: h:tp-link:tl-mr3220
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10
2017
Vulnerability Xss – TP-LINK TL-MR3220
First you go to ( http://IP:PORT/ ) In the 'Wireless MAC Filtering' tab. Will add a new MAC Address. In 'Description' it will put the script ( <script>alert('XSS')</script> ) and complete the registration.
Mitigation:
Ensure that user-supplied input is properly sanitized and validated before being used in the application.