vendor:
Router WRN150
by:
Prof. Joas Antonio
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Router WRN150
Affected Version From: 1.0.18
Affected Version To: 1.0.18
Patch Exists: NO
Related CWE: CVE-2019-17411
CPE: a:intelbras:router_wrn150:1.0.18
Platforms Tested: Windows
2019
Intelbras Router WRN150 1.0.18 – Persistent Cross-Site Scripting
The Intelbras Router WRN150 version 1.0.18 is vulnerable to persistent cross-site scripting. An attacker can inject malicious scripts into the Service Name and Server Name fields, allowing for the execution of arbitrary code in the user's browser.
Mitigation:
The vendor has not provided a patch for this vulnerability. Users are advised to avoid using the affected fields or to sanitize user input to prevent script injection.