Luxul XWR-600 Cross-Site Scripting Vulnerability in Web Administration Interface
Vulnerability
A stored cross-site scripting vulnerability has been identified in the Luxul XWR-600 router, affecting firmware versions through 4.0.1. The issue arises in the Web Administration Interface, where user input in the Guest Network/Wireless Profile SSID fields is not properly sanitized. This allows an attacker to inject malicious JavaScript that is executed in the administrator's browser when the page is accessed. The vulnerability can be exploited remotely, but requires authentication and user interaction.
Impact
Exploitation of this vulnerability allows authenticated attackers to execute arbitrary JavaScript in the administrator's browser, potentially leading to unauthorized configuration changes or the injection of persistent malicious content.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
