Skip to content

Instantly share code, notes, and snippets.

@adeshkolte
Last active January 28, 2020 10:18
Show Gist options
  • Save adeshkolte/983bcadd82cc1fd60333098eb646ef68 to your computer and use it in GitHub Desktop.
Save adeshkolte/983bcadd82cc1fd60333098eb646ef68 to your computer and use it in GitHub Desktop.
CVE-2020-7997 ASUS WRT-AC66U 3 RT 3.0.0.4 Cross Site Scripting
Author: Adesh Nandkishor KOlte
> Vulnerable Parameter:Client Name
>
> PoC: Exploitation
"><svg onload=prompt(/xss/);>
>
> [Vulnerability Type]
> Cross Site Scripting (XSS)
>
> ------------------------------------------
>
> [Vendor of Product]
> ASUS Product: WRT - Wireless Router (UI) 3.0.0.4.
>
> ------------------------------------------
>
> [Affected Product Code Base]
> ASUS WRT-AC66U 3 - ASUS WRT-AC66U 3
>
> ------------------------------------------
>
> [Affected Component]
> multiple cross site scripting vulnerabilities
> ASUS Wireless Router RT Firmware v3.0.0
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> [Discoverer]
> Adesh Nandkishor Kolte
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment