cbcvebase.
CVE-2021-43702
published 2022-07-05

CVE-2021-43702: ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an…

PriorityP338critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.91%
55.8th percentile
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.

Affected

93 ranges· showing 25
VendorProductVersion rangeFixed in
asus4g-ac53u_firmware
asus4g-ac68u_firmware
asusrog_rapture_gt-ac2900_firmware
asusrog_rapture_gt-ac5300_firmware
asusrog_rapture_gt-ax11000_firmware
asusrt-ac1200_firmware
asusrt-ac1200e_firmware
asusrt-ac1200g_+_firmware
asusrt-ac1200g_firmware
asusrt-ac1200gu_firmware
asusrt-ac1200hp_firmware
asusrt-ac1300g_+_firmware
asusrt-ac1300uhp_firmware
asusrt-ac1750_b1_firmware
asusrt-ac1750_firmware
asusrt-ac1900_firmware
asusrt-ac1900p_firmware
asusrt-ac1900u_firmware
asusrt-ac2200_firmware
asusrt-ac2400_firmware
asusrt-ac2600_firmware
asusrt-ac2900_firmware
asusrt-ac3100_firmware
asusrt-ac3200_firmware
asusrt-ac51u_+_firmware

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.