S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-38702 Scanner

CVE-2021-38702 scanner - Cross-Site Scripting (XSS) vulnerability in Cyberoam NetGenie C0101B1-20141120-NG11VO devices

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-38702
6.1
CVSS

Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Cyberoam NetGenie C0101B1 is a device used to safeguard home and small office networks. It is primarily designed for providing internet security to users at an affordable price. This tool offers several built-in features, like firewall, parental control, web filtering and VPN connectivity, to ensure secure connections between devices and the internet. The Cyberoam NetGenie devices are perfect for those needing basic internet security measures for their home or small business.

However, there is a significant flaw with this product. The vulnerability code CVE-2021-38702, has been detected in the Cyberoam NetGenie C0101B1-20141120-NG11VO devices even up to August 14, 2021. This vulnerability allows for attacks involving Cross Site Scripting (XSS) against a specific web page, tweb/ft.php?u= [XSS], which can be easily exploited.

When exploited, the CVE-2021-38702 vulnerability in Cyberoam NetGenie C0101B1-20141120-NG11VO devices can lead to the injection of arbitrary web script code into a victim's browser, thereby giving access to their internet activity to the attacker. With this vulnerability, attackers can steal sensitive data from a victim, such as passwords, credit card numbers, or other confidential information. This flaw in the device puts users' privacy and security at risk.

With the pro features of the s4e.io platform, users can quickly and easily stay up-to-date with vulnerabilities in their digital assets. By utilizing this service, users can address vulnerabilities as soon as they are discovered, ensuring the protection of their personal data and privacy. With comprehensive vulnerability scans of networks and devices, s4e.io provides a holistic approach to internet security, with the ability to cover a wide range of exploitable areas and offer suggested solutions. 

 

REFERENCES

Solution Advice

To protect against the vulnerability, you should implement the following measures:

  • Update the firmware of the Cyberoam NetGenie device as soon as possible. 
  • Disable and remove any unused features or services on the device. 
  • Only allow trusted sites to establish connections with your device. 
  • Disable any remote access functionality unless it is necessary. 
  • Set a strong password for the device that can't be easily guessed.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-38702 scanner - Cross-Site Scripting (XSS) vulnerability in Cyberoam NetGenie C0101B1-20141120-NG11VO devices | S4E