CVE-2017-9243
MEDIUMAries QWR-1104 Wireless-N Router Firmware WRC.253.2.0913 - Cross-Site Scripting via Wireless Site Survey AP Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9243. PoCs published by Touhid M.Shaikh.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the Aries QWR-1104 Wireless-N Router's Wireless Site Survey page. The attacker creates a malicious hotspot with a name containing JavaScript code, which executes when the target router's admin views the Site Survey page.
Description
Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploitable with the name of an access point.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the Aries QWR-1104 Wireless-N Router's Wireless Site Survey page. The attacker creates a malicious hotspot with a name containing JavaScript code, which executes when the target router's admin views the Site Survey page.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N