PT-2019-13423 · D Link · Dir-655

Publicado

2019-07-11

·

Atualizado

2019-07-12

·

CVE-2019-13562

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-655 C devices before version 3.02B05 BETA03
Description The issue allows for XSS, as demonstrated by the "/www/ping response.cgi" API endpoint with the ping ipaddr parameter, the "/www/ping6 response.cgi" API endpoint with the ping6 ipaddr parameter, and the "/www/apply sec.cgi" API endpoint with the html response return page parameter.
Recommendations For versions prior to 3.02B05 BETA03, update to version 3.02B05 BETA03 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoints "/www/ping response.cgi", "/www/ping6 response.cgi", and "/www/apply sec.cgi" until the update is applied. Avoid using the parameters ping ipaddr, ping6 ipaddr, and html response return page in the affected API endpoints until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13562

Produtos afetados

Dir-655