S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-21801 Scanner

CVE-2021-21801 scanner - Cross-Site Scripting (XSS) vulnerability in Advantech R-SeeNet

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-21801
6.1
CVSScritical
Exploitable remotely over the internet · no authentication required · user interaction needed.

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Advantechby n/a
Advantech R-SeeNet 2.4.12 (20.10.2020)
Updated Aug 21, 2026View on NVD →
Detail

Advantech R-SeeNet is a web application used for device management, monitoring, and visualization. It provides a user-friendly interface for managing industrial automation devices, such as programmable logic controllers (PLCs), HMIs, and other devices connected to a network. With its advanced features, the Advantech R-SeeNet aims to provide enhanced efficiency and productivity to industrial automation processes.

One of the critical vulnerabilities detected in the Advantech R-SeeNet is CVE-2021-21801. The vulnerability is present in the device_graph_page.php script and can allow an attacker to execute arbitrary JavaScript code on the target system. This can lead to unauthorized access to sensitive information, alteration of system configurations, and even complete system takeover.

When exploited, the CVE-2021-21801 vulnerability can be highly damaging to a system. An attacker can use this vulnerability to perform various malicious actions, including stealing confidential data, manipulating device settings, installing malware, and disrupting normal system operations. Furthermore, the exploitation of this vulnerability can lead to significant financial losses, downtime, and reputational damage.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides advanced scanning tools, real-time alerts, and expert analysis to identify and remediate vulnerabilities promptly. By using this platform, businesses can ensure that their digital assets are secure and protected against cybersecurity threats.

 

REFERENCES

Solution Advice

To safeguard against the CVE-2021-21801 vulnerability, it is essential to take specific precautions, such as:

  • Update the Advantech R-SeeNet to the latest version.
  • Implement access control mechanisms to prevent unauthorized access to the system.
  • Regularly monitor the system for any suspicious activity.
  • Use robust and reliable antivirus software to detect and prevent malware attacks.
  • Conduct regular security assessments to identify and mitigate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-21801 scanner - Cross-Site Scripting (XSS) vulnerability in Advantech R-SeeNet | S4E