CVE-2021-21803 is a Cross-Site Scripting (XSS) vulnerability found in the device_graph_page.php script of Advantech R-SeeNet web applications. An attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript code within their browser. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction (UI:R) and has low impact on confidentiality and integrity (C:L, I:L). While not listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 98/100 suggest a significant likelihood of exploitation. Although no Metasploit or ExploitDB modules exist, Nuclei templates are available, and it has garnered community discussion and media coverage, indicating awareness among researchers and potential attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.12CPE matchmatch criteria | cpe:2.3:a:advantech:r-seenet:2.4.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.