CVE-2015-1437

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/02/2015
Last modified:
12/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in Asus RT-N10+ D1 router with firmware 2.1.1.1.70 allow remote attackers to inject arbitrary web script or HTML via the flag parameter to (1) result_of_get_changed_status.asp or (2) error_page.htm.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:asus:rt-n10\+d1_firmware:2.1.1.1.70:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-n10\+d1:*:*:*:*:*:*:*:*