← Vulnerability feed

Vulnerability record · CVE-2021-21803 · published 16 July 2021

CVE-2021-21803: Advantech r-seenet cross-site scripting vulnerability

Advantech · R Seenet

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

6.1 CVSS 3.1 Medium EPSS 7.9% · top 5.5% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
7.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21803 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5642Advantech r-seenet information exposure vulnerabilityAdvantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive informa…EPSS 17%9.8CVE-2023-2611Advantech r-seenet hard-coded credentials vulnerabilityAdvantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a passwor…EPSS 0.67%9.8CVE-2022-3385Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stac…EPSS 1.3%9.8CVE-2022-3386Advantech r-seenet stack-based buffer overflow vulnerabilityAdvantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename t…EPSS 1.3%9.8CVE-2021-21805Advantech R-SeeNet ping.php OS command injectionAdvantech R-SeeNet v2.4.12 (20.10.2020) contains an OS command injection flaw in the ping.php script. A crafted HTTP request can cause arbitrary OS c…EPSS 70%analysed9.8CVE-2021-21804Advantech r-seenet php remote file inclusion vulnerabilityA local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr…EPSS 3.7%8.8CVE-2021-21915Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%8.8CVE-2021-21916Advantech r-seenet sql injection vulnerabilityAn exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP req…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-21803), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.