CVE-2021-32426

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/06/2021
Last modified:
24/06/2021

Description

In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:trendnet:tw100-s4w1ca_firmware:2.3.32:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tw100-s4w1ca:-:*:*:*:*:*:*:*