vendor:
D1500 Home Router
by:
Securityium
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: D1500 Home Router
Affected Version From: V1.0.0.21_1.0.1PE
Affected Version To: V1.0.0.21_1.0.1PE
Patch Exists: NO
Related CWE: N/A
CPE: h:netgear:d1500-100pes-a
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: NetGear D1500 Home Router
2018
NetGear D1500 V1.0.0.21_1.0.1PE – ‘Wireless Repeater’ Stored Cross-Site Scripting (XSS)
If any admin is logged on the router admin panel. if he/she try to connect any other SSID for Wireless Repeating Function. that time they need to check available SSID surrounding. that name is not sanitized properly before showing on the web's admin panel which leads to Stored XSS.
Mitigation:
Input validation should be done to sanitize the user input before displaying it on the web page.