Our security team has informed us that the 3504 running 8.10.130 is showing as vulnerable for the issue identified in CVE-2020-11022
In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
Interestingly I found this bug: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvu12372 opened for CVE-2015-9251, CVE-2019-11358 but right at the end of the notes says: Related : CVE-2020-11022 I think you need to contact Cisco PSIRT or TAC to confirm whether this means AireOS is affected by CVE-2020-11022 or not (and ask them to update the bug notes to clarify). Either way it's fixed in 8.10(139.14) so not in a public release yet and it's classified as Severity: 6 Enhancement so clearly not considered to be high risk which I guess means you can't do much harm with it on AireOS.