4.3
CVSSv2

CVE-2018-15875

Published: 25/08/2018 Updated: 23/04/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows malicious users to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-615_firmware 20.07

Github Repositories

CVE Disclosures

CVE-2019-14363 -> Netgear WNDR3400v3 Stack-Based Buffer Overflow via UPnP SSDP CVE-2018-15874 -> D-Link DIR-615 XSS Via DHCP CVE-2018-15875 -> D-Link DIR-615 XSS Via the UPnP Protocol