Vulnerability record · CVE-2021-21801 · published 16 July 2021
CVE-2021-21801: Advantech R-SeeNet device_graph_page.php reflected XSS
Advantech · R Seenet
The device_graph_page.php script in Advantech R-SeeNet reflects attacker-controlled input into a page without proper encoding, allowing arbitrary JavaScript execution in a victim's browser. Because the script is part of a web management application, successful exploitation can run script in the context of an authenticated session.
Description
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 3.1 base score is 6.1 (Medium) with user interaction required, but EPSS is high and an exploit reference exists.
What it is
The device_graph_page.php script in Advantech R-SeeNet reflects attacker-controlled input into a page without proper encoding, allowing arbitrary JavaScript execution in a victim's browser. Because the script is part of a web management application, successful exploitation can run script in the context of an authenticated session.
Impact
An attacker can execute arbitrary JavaScript in the victim's browser, potentially stealing session cookies, performing actions as the victim, or redirecting the victim to malicious content. The CVSS scope change indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL to device_graph_page.php; no authentication is required to deliver the payload, but the victim must click or visit the crafted link (UI:R).
Exploitation
Not listed in CISA KEV. EPSS probability is 0.63415 (99.17th percentile), and the reference is tagged Exploit, indicating public exploit information exists.
What to do
- Apply the vendor patch or update for Advantech R-SeeNet as soon as it is available.
- Restrict network access to the R-SeeNet web interface to trusted management networks.
- Deploy a WAF or input filtering rule to block script payloads targeting device_graph_page.php.
- Encode or validate all user-supplied input reflected by device_graph_page.php.
- Educate users not to click untrusted links to the R-SeeNet application.
Detection
- Monitor web logs for requests to device_graph_page.php containing script tags or encoded JavaScript in parameters.
- Alert on outbound or inline script execution anomalies in the R-SeeNet web application.
- Review browser or proxy logs for referrals to device_graph_page.php from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1272 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2021-1272 | ExploitThird Party Advisory |
Track CVE-2021-21801 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21801), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.