Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.Referenceshttps://jvn.jp/en/jp/JVN92237169/index.htmlhttp://corega.jp/support/security/20161111_wlr300nx.htmhttp://www.securityfocus.com/bid/94248