Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploitable with the name of an access point.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://touhidshaikh.com/blog/poc/qwr-1104-wireless-n-router-xss/ | third party advisory exploit |
https://www.exploit-db.com/exploits/42075/ | third party advisory vdb entry exploit |