Back to Database
Status published
Medium
CVE-2021-44148
GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow...
Vulnerability Description
GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-44148
Credits & Attribution
No credits recorded in the NVD database.
More from gl-inet
View All →CVE-2022-44212
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to...
Unknown
0
CVE-2022-44211
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote...
Unknown
0
CVE-2022-42055
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management...
Unknown
0
CVE-2022-42054
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT...
Unknown
0
CVE-2022-31898
gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered...
Unknown
0
Affected Vendor
gl-inet
View all reports →Affected Software
gl-ar150 firmware
Vulnerable Versions:
2.0
Timeline
Official Publish:
December 7th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.