Cross-site scripting in NETGEAR products - #VU61868
Published: April 5, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
GS310TP
MS510TXM
MS510TXUP
GS724TPv2
GS728TPv2
GS728TPPv2
GS752TPv2
GS752TPP
GS110TPv3
GS110TPP
GS108Tv3
Remediation
GS310TP - update to 1.0.4.4
MS510TXM - update to 1.0.4.6
MS510TXUP - update to 1.0.4.6
GS724TPv2 - update to 2.0.7.4
GS728TPv2 - update to 6.0.9.3
GS728TPPv2 - update to 6.0.9.3
GS752TPv2 - update to 6.0.9.3
GS752TPP - update to 6.0.9.3
GS110TPv3 - update to 7.0.8.4
GS110TPP - update to 7.0.8.4
GS108Tv3 - update to 7.0.8.4