CVE-2021-20137

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/12/2021
Last modified:
13/12/2021

Description

A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gryphonconnect:gryphon_tower_firmware:*:*:*:*:*:*:*:* 04.0004.12 (including)
cpe:2.3:h:gryphonconnect:gryphon_tower:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools