← Vulnerability feed

Vulnerability record · CVE-2021-21801 · published 16 July 2021

CVE-2021-21801: Advantech R-SeeNet device_graph_page.php reflected XSS

Advantech · R Seenet

The device_graph_page.php script in Advantech R-SeeNet reflects attacker-controlled input into a page without proper encoding, allowing arbitrary JavaScript execution in a victim's browser. Because the script is part of a web management application, successful exploitation can run script in the context of an authenticated session.

6.1 CVSS 3.1 Medium EPSS 63% · top 0.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS 3.1 base score is 6.1 (Medium) with user interaction required, but EPSS is high and an exploit reference exists.

What it is

The device_graph_page.php script in Advantech R-SeeNet reflects attacker-controlled input into a page without proper encoding, allowing arbitrary JavaScript execution in a victim's browser. Because the script is part of a web management application, successful exploitation can run script in the context of an authenticated session.

Impact

An attacker can execute arbitrary JavaScript in the victim's browser, potentially stealing session cookies, performing actions as the victim, or redirecting the victim to malicious content. The CVSS scope change indicates the impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via a crafted URL to device_graph_page.php; no authentication is required to deliver the payload, but the victim must click or visit the crafted link (UI:R).

Exploitation

Not listed in CISA KEV. EPSS probability is 0.63415 (99.17th percentile), and the reference is tagged Exploit, indicating public exploit information exists.

What to do

  • Apply the vendor patch or update for Advantech R-SeeNet as soon as it is available.
  • Restrict network access to the R-SeeNet web interface to trusted management networks.
  • Deploy a WAF or input filtering rule to block script payloads targeting device_graph_page.php.
  • Encode or validate all user-supplied input reflected by device_graph_page.php.
  • Educate users not to click untrusted links to the R-SeeNet application.

Detection

  • Monitor web logs for requests to device_graph_page.php containing script tags or encoded JavaScript in parameters.
  • Alert on outbound or inline script execution anomalies in the R-SeeNet web application.
  • Review browser or proxy logs for referrals to device_graph_page.php from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21801 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5642Advantech r-seenet information exposure vulnerabilityAdvantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…EPSS 17%9.8CVE-2023-2611Advantech r-seenet hard-coded credentials vulnerabilityAdvantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a passwor…EPSS 0.67%9.8CVE-2022-3385Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stac…EPSS 1.3%9.8CVE-2022-3386Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename t…EPSS 1.3%9.8CVE-2021-21805Advantech R-SeeNet ping.php OS command injectionAdvantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS c…EPSS 70%analysed9.8CVE-2021-21804Advantech r-seenet php remote file inclusion vulnerabilityA local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…EPSS 3.7%8.8CVE-2021-21915Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%8.8CVE-2021-21916Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-21801), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.