6.1
CVSSv3

CVE-2018-6528

Published: 06/03/2018 Updated: 08/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote malicious users to read a cookie via a crafted receiver parameter to soap.cgi.

Vulnerable Product Search on Vulmon Subscribe to Product

dlink dir-860l_firmware

dlink dir-865l_firmware

dlink dir-868l_firmware

Github Repositories

日前我发现了D-Link DIR 880L/865L/868L/860L路由器存在多个XSS和命令注入漏洞,最主要的问题是路由器未对用户输入进行检查,导致恶意数据请求被执行,最终被远程攻击者控制整个设备。

0x00 Product Description Dlink is a multinational networking equipment manufacturing corporation The Dlink 860L/865L/868L/880L are wireless "Cloud" Router The vulnerabilities details are as follows: Vendor: D-Link Devices: DIR-880 REVA / DIR-868 REVA / DIR-865 / DIR-860 REVA Firmware: DIR-880L_REVA_FIRMWARE_PATCH_108B04 DIR868LA1_FW112b04 DIR-865L_REVA_FIRMWARE_PAT