Vulnerability Details CVE-2021-20847
Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.7%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-20847
-
cpe:2.3:h:nttdocomo:wi-fi_station_sh-52a:-
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11g
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11j
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11k
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_11l
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26f
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26g
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_1_26j
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_2_03b
-
cpe:2.3:o:nttdocomo:wi-fi_station_sh-52a_firmware:38jp_2_03c