Cross-Site Scripting Vulnerability in D-Link DIR-655 C Devices
CVE-2019-13562
6.1MEDIUM
Summary
The D-Link DIR-655 C devices prior to version 3.02B05 BETA03 are affected by a Cross-Site Scripting (XSS) vulnerability. This issue could be exploited via crafted parameters in specific CGI endpoints, such as /www/ping_response.cgi, /www/ping6_response.cgi, and /www/apply_sec.cgi, allowing an attacker to execute arbitrary scripts in the context of the user’s browser. Consequently, this may lead to unauthorized access and data manipulation, highlighting the need for prompt updates and patches to ensure device security.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved