XSS on the PIX-Link Repeater/Router LV-WR07 with firmware v28K.Router.20170904 allows attackers to steal credentials without being connected to the network. The attack vector is a crafted ESSID, as demonstrated by the wireless.htm SET2 parameter.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24104
Reference (s):
- http://n0hat.blogspot.com/2020/07/stored-cross-site-scripting-xss-at-pix.html

