4.3
CVSSv2

CVE-2018-6212

Published: 20/06/2018 Updated: 26/04/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filtration for special characters in the "Search" field and incorrect processing of the XMLHttpRequest object.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

d-link dir-620_firmware 1.0.3

d-link dir-620_firmware 1.0.37

d-link dir-620_firmware 1.3.1

d-link dir-620_firmware 1.3.3

d-link dir-620_firmware 1.3.7

d-link dir-620_firmware 1.4.0

d-link dir-620_firmware 2.0.22