# Exploit Title: NetGear D1500 V1.0.0.21_1.0.1PE - 'Wireless Repeater' Stored Cross-Site Scripting (XSS) # Date: 21 Dec 2018 # Exploit Author: Securityium # Vendor Homepage: https://www.netgear.com/ # Version: V1.0.0.21_1.0.1PE # Tested on: NetGear D1500 Home Router # Contact: assessors@securityium.com Version : Hardware version: D1500-100PES-A Firmware Version : V1.0.0.21_1.0.1PE Step to Reproduce Video: https://www.youtube.com/watch?v=JcRYxH93E5E Tested Network: Local LAN SSID Details: Attacker SSID : For routers admin 3) Logged in as admin. 2) Go to Advanced --> Advanced Setup --> Wireless Repeating Function 3) Enable Wireless Repeating Function 4) click on check. wait for the checking scan to finish and display the surrounding networks list.