CVE-2021-28160
Stored XSS on Acexy (BoyaMicro) Wireless-N WiFi Repeater 28.08.06.1 version 1.0 devices can occur via a malformed SSID field during scanning for nearby access points, which also occurs when a device’s user visits the Repeater Wizard web management section. This enables an attacker to steal LAN credentials without being connected to the device.
Source: CVE-2021-28160