← Vulnerability feed

Vulnerability record · CVE-2021-21800 · published 16 July 2021

CVE-2021-21800: Advantech r-seenet cross-site scripting vulnerability

Advantech · R Seenet

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

6.1 CVSS 3.1 Medium EPSS 14% · top 3.6% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21800 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5642Advantech r-seenet information exposure vulnerabilityAdvantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…EPSS 17%9.8CVE-2023-2611Advantech r-seenet hard-coded credentials vulnerabilityAdvantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a passwor…EPSS 0.67%9.8CVE-2022-3385Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stac…EPSS 1.3%9.8CVE-2022-3386Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename t…EPSS 1.3%9.8CVE-2021-21805Advantech R-SeeNet ping.php OS command injectionAdvantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS c…EPSS 70%analysed9.8CVE-2021-21804Advantech r-seenet php remote file inclusion vulnerabilityA local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…EPSS 3.7%8.8CVE-2021-21915Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%8.8CVE-2021-21916Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-21800), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.