← back
CVE-2017-2148

CVE-2017-2148

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
In short

A router's web interface allows attackers who are already logged in to inject malicious scripts that could steal information or perform unwanted actions. This happens because the device doesn't properly validate user input before displaying it.

Technical detail

Cross-site scripting (XSS) vulnerability in WN-AC1167GR firmware ≤1.04 allows authenticated attackers to inject arbitrary JavaScript or HTML through unspecified input vectors. The vulnerability requires valid credentials but enables session hijacking, credential theft, or unauthorized configuration changes via browser-based exploitation.

Summary generated and translated by AI from the official description.
Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.