Linksys E5600 Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in the Linksys E5600 AC1200 WiFi Router, specifically in the web management interface of version 1.1.0.26. This vulnerability allows attackers to inject arbitrary web scripts or HTML into the hostname and domainName parameters. The injected payload is executed when an administrator accesses the System Status page, potentially leading to session hijacking, credential theft, and unauthorized changes to router settings.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
