Blind Cross-Site Scripting Vulnerability in D-Link DIR-615 Router
CVE-2019-19742
Key Information:
- Vendor
D-Link
- Status
- Vendor
- CVE Published:
- 18 December 2019
Badges
What is CVE-2019-19742?
The D-Link DIR-615 router is susceptible to a blind Cross-Site Scripting (XSS) vulnerability through the User Account Configuration page. An attacker can exploit this weakness by injecting malicious scripts through the name field, potentially leading to unauthorized access or session hijacking. This vulnerability highlights the importance of securing user input fields to prevent exploitation by malicious users and ensuring that devices are regularly updated to mitigate known security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved