VYPR
Unrated severityNVD Advisory· Published Mar 4, 2022· Updated Aug 4, 2024

CVE-2021-46382

CVE-2021-46382

Description

Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

Root cause

"The web interface of the Netgear WAC120 lacks proper input sanitization or output encoding, allowing unauthenticated stored or reflected cross-site scripting."

Attack vector

An unauthenticated attacker can inject arbitrary JavaScript into the web interface of the Netgear WAC120 AC Access Point. Because the XSS is unauthenticated, no login or prior access is required. The attacker would craft a malicious link or payload that, when visited by an administrator or other user, executes in the context of the device's management interface. This could lead to session hijacking, clipboard hijacking, or other client-side attacks. [ref_id=1]

Affected code

The advisory does not specify the exact file or function within the Netgear WAC120 firmware that is vulnerable. The only reference provided is the general NETGEAR security advisory page, which lacks technical details about the affected code path.

What the fix does

The advisory does not include a patch diff or specific remediation instructions. NETGEAR's security policy states that fixes are developed for supported products and published in monthly security patch updates. Users should check the NETGEAR Security Advisories page for a firmware update that addresses this CVE. [ref_id=1]

Preconditions

  • networkThe attacker must be able to send a crafted HTTP request to the web management interface of the Netgear WAC120 (e.g., via a malicious link or direct network access).
  • authNo authentication is required; the XSS is exploitable without valid credentials.

Generated on May 30, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

2

News mentions

0

No linked articles in our index yet.