// For flags

CVE-2021-20680

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 and earlier, Aterm WG1800HP4 firmware Ver.1.3.1 and earlier, Aterm WG1800HP3 firmware Ver.1.5.1 and earlier, Aterm WG1200HS2 firmware Ver.2.5.0 and earlier, Aterm WG1200HP3 firmware Ver.1.3.1 and earlier, Aterm WG1200HP2 firmware Ver.2.5.0 and earlier, Aterm W1200EX firmware Ver.1.3.1 and earlier, Aterm W1200EX-MS firmware Ver.1.3.1 and earlier, Aterm WG1200HS firmware all versions Aterm WG1200HP firmware all versions Aterm WF800HP firmware all versions Aterm WF300HP2 firmware all versions Aterm WR8165N firmware all versions Aterm W500P firmware all versions, and Aterm W300P firmware all versions) allows remote attackers to inject arbitrary script or HTML via unspecified vectors.

Una vulnerabilidad de tipo Cross-site scripting en los dispositivos NEC Aterm (Aterm WG1900HP2 versiones de firmware Ver.1.3.1 y anterior, Aterm WG1900HP versiones de firmware Ver.2.5.1 y anterior, Aterm WG1800HP4 versiones de firmware Ver.1.3.1 y anterior, Aterm WG1800HP3 versiones de firmware Ver.1.5. 1 y anterior, Aterm WG1200HS2 versiones de firmware Ver.2.5.0 y anterior, Aterm WG1200HP3 versiones de firmware Ver.1.3.1 y anterior, Aterm WG1200HP2 versiones de firmware Ver.2.5.0 y anterior, Aterm W1200EX versiones de firmware Ver.1.3.1 y anterior, Aterm W1200EX -MS versiones de firmware Ver.1.3.1 y anteriores, Aterm WG1200HS todas las versiones de firmware, Aterm WG1200HP todas las versiones de firmware, Aterm WF800HP todas las versiones de firmware, Aterm WF300HP2 todas las versiones de firmware, Aterm WR8165N todas las versiones de firmware, Aterm W500P todas las versiones y Aterm W300P todas las versiones de firmware) permite a atacantes remotos inyectar script o HTML arbitrario por medio de vectores no especificados

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-04-26 CVE Published
  • 2024-04-29 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nec
Search vendor "Nec"
Aterm Wg1900hp2 Firmware
Search vendor "Nec" for product "Aterm Wg1900hp2 Firmware"
<= 1.3.1
Search vendor "Nec" for product "Aterm Wg1900hp2 Firmware" and version " <= 1.3.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1900hp2
Search vendor "Nec" for product "Aterm Wg1900hp2"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1900hp Firmware
Search vendor "Nec" for product "Aterm Wg1900hp Firmware"
<= 2.5.1
Search vendor "Nec" for product "Aterm Wg1900hp Firmware" and version " <= 2.5.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1900hp
Search vendor "Nec" for product "Aterm Wg1900hp"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1800hp4 Firmware
Search vendor "Nec" for product "Aterm Wg1800hp4 Firmware"
<= 1.3.1
Search vendor "Nec" for product "Aterm Wg1800hp4 Firmware" and version " <= 1.3.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1800hp4
Search vendor "Nec" for product "Aterm Wg1800hp4"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1800hp3 Firmware
Search vendor "Nec" for product "Aterm Wg1800hp3 Firmware"
<= 1.5.1
Search vendor "Nec" for product "Aterm Wg1800hp3 Firmware" and version " <= 1.5.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1800hp3
Search vendor "Nec" for product "Aterm Wg1800hp3"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1200hs3 Firmware
Search vendor "Nec" for product "Aterm Wg1200hs3 Firmware"
<= 1.1.2
Search vendor "Nec" for product "Aterm Wg1200hs3 Firmware" and version " <= 1.1.2"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1200hs3
Search vendor "Nec" for product "Aterm Wg1200hs3"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1200hs2 Firmware
Search vendor "Nec" for product "Aterm Wg1200hs2 Firmware"
<= 2.5.0
Search vendor "Nec" for product "Aterm Wg1200hs2 Firmware" and version " <= 2.5.0"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1200hs2
Search vendor "Nec" for product "Aterm Wg1200hs2"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1200hp3 Firmware
Search vendor "Nec" for product "Aterm Wg1200hp3 Firmware"
<= 1.3.1
Search vendor "Nec" for product "Aterm Wg1200hp3 Firmware" and version " <= 1.3.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1200hp3
Search vendor "Nec" for product "Aterm Wg1200hp3"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1200hp2 Firmware
Search vendor "Nec" for product "Aterm Wg1200hp2 Firmware"
<= 2.5.0
Search vendor "Nec" for product "Aterm Wg1200hp2 Firmware" and version " <= 2.5.0"
-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1200hp2
Search vendor "Nec" for product "Aterm Wg1200hp2"
--
Safe
Nec
Search vendor "Nec"
Aterm W1200ex Firmware
Search vendor "Nec" for product "Aterm W1200ex Firmware"
<= 1.3.1
Search vendor "Nec" for product "Aterm W1200ex Firmware" and version " <= 1.3.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm W1200ex
Search vendor "Nec" for product "Aterm W1200ex"
--
Safe
Nec
Search vendor "Nec"
Aterm W1200ex-ms Firmware
Search vendor "Nec" for product "Aterm W1200ex-ms Firmware"
<= 1.3.1
Search vendor "Nec" for product "Aterm W1200ex-ms Firmware" and version " <= 1.3.1"
-
Affected
in Nec
Search vendor "Nec"
Aterm W1200ex-ms
Search vendor "Nec" for product "Aterm W1200ex-ms"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1200hs Firmware
Search vendor "Nec" for product "Aterm Wg1200hs Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1200hs
Search vendor "Nec" for product "Aterm Wg1200hs"
--
Safe
Nec
Search vendor "Nec"
Aterm Wg1200hp Firmware
Search vendor "Nec" for product "Aterm Wg1200hp Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm Wg1200hp
Search vendor "Nec" for product "Aterm Wg1200hp"
--
Safe
Nec
Search vendor "Nec"
Aterm Wf800hp Firmware
Search vendor "Nec" for product "Aterm Wf800hp Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm Wf800hp
Search vendor "Nec" for product "Aterm Wf800hp"
--
Safe
Nec
Search vendor "Nec"
Aterm Wf300hp2 Firmware
Search vendor "Nec" for product "Aterm Wf300hp2 Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm Wf300hp2
Search vendor "Nec" for product "Aterm Wf300hp2"
--
Safe
Nec
Search vendor "Nec"
Aterm Wr8165n Firmware
Search vendor "Nec" for product "Aterm Wr8165n Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm Wr8165n
Search vendor "Nec" for product "Aterm Wr8165n"
--
Safe
Nec
Search vendor "Nec"
Aterm W500p Firmware
Search vendor "Nec" for product "Aterm W500p Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm W500p
Search vendor "Nec" for product "Aterm W500p"
--
Safe
Nec
Search vendor "Nec"
Aterm W300p Firmware
Search vendor "Nec" for product "Aterm W300p Firmware"
*-
Affected
in Nec
Search vendor "Nec"
Aterm W300p
Search vendor "Nec" for product "Aterm W300p"
--
Safe