Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
2016-05-14T16:59:01.197
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | iodata | wn-g300r2 | - | No |
Operating System | iodata | wn-g300r2_firmware | ≤ 1.12 | Yes |
Hardware | iodata | wn-g300r3 | - | No |
Operating System | iodata | wn-g300r3_firmware | ≤ 1.01 | Yes |
Hardware | iodata | wn-g300r | - | No |
Operating System | iodata | wn-g300r_firmware | ≤ 1.12 | Yes |