CVE-2013-3069
published 2014-04-25CVE-2013-3069: Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script…
PriorityP412low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.09%
61.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1) UserName or (2) Password to the NAS User Setup page, (3) deviceName to USB_advanced.htm, or (4) Network Key to the Wireless Setup page.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | wndr4700_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear WNDR4700 -/1.0.0.34 USB_advanced.htm deviceName Stored cross site scripting (OSVDB-97697)
vuldb·2026-05-12·CVSS 3.5
CVE-2013-3069 [LOW] Netgear WNDR4700 -/1.0.0.34 USB_advanced.htm deviceName Stored cross site scripting (OSVDB-97697)
A vulnerability was found in Netgear WNDR4700 -/1.0.0.34. It has been declared as problematic. The affected element is an unknown function of the file USB_advanced.htm. Such manipulation of the argument deviceName leads to cross site scripting (Stored).
This vulnerability is listed as CVE-2013-3069. The attack may be performed from remote. There is no available exploit.
VulDB
Netgear WNDR4700 -/1.0.0.34 Wireless Setup Page Network Key Stored cross site scripting (OSVDB-97698)
vuldb·2026-05-12·CVSS 3.5
CVE-2013-3069 [LOW] Netgear WNDR4700 -/1.0.0.34 Wireless Setup Page Network Key Stored cross site scripting (OSVDB-97698)
A vulnerability was found in Netgear WNDR4700 -/1.0.0.34. It has been rated as problematic. The impacted element is an unknown function of the file Wireless Setup Page. Performing a manipulation of the argument Network Key results in cross site scripting (Stored).
This vulnerability is cataloged as CVE-2013-3069. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
GHSA-7p6q-wh2x-4x7c: Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1
ghsa_unreviewed·2022-05-17
CVE-2013-3069 [LOW] CWE-79 GHSA-7p6q-wh2x-4x7c: Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1
Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticated users to inject arbitrary web script or HTML via the (1) UserName or (2) Password to the NAS User Setup page, (3) deviceName to USB_advanced.htm, or (4) Network Key to the Wireless Setup page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-04-25
Published