CVE-2021-21801 is a Cross-Site Scripting (XSS) vulnerability affecting Advantech R-SeeNet web applications, specifically within the device_graph_page.php script. This medium-severity vulnerability (CVSS 6.1) allows for arbitrary JavaScript code execution when a victim visits a specially crafted URL, requiring user interaction but having a low impact on confidentiality and integrity. While not listed in CISA's KEV catalog, its high EPSS and FAUCET Risk Scores indicate a significant likelihood of exploitation. Although no Metasploit or ExploitDB exploits exist, Nuclei templates are available, and it has garnered community discussion and media coverage, including reports of its targeting in OT scanning activities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.12CPE matchmatch criteria | cpe:2.3:a:advantech:r-seenet:2.4.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.