PT-2018-17615 · D Link · D-Link Dir-860L+2
Kaixiang Zhang
·
Published
2018-03-06
·
Updated
2023-11-08
·
CVE-2018-6529
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-868L versions DIR868LA1 FW112b04 and earlier
D-Link DIR-865L versions DIR-865L REVA FIRMWARE PATCH 1.08.B01 and earlier
D-Link DIR-860L versions DIR860LA1 FW110b04 and earlier
Description
The issue allows remote attackers to read a cookie via a crafted
Treturn parameter to the soap.cgi endpoint. This is due to an XSS vulnerability in the htdocs/webinc/js/bsc sms inbox.php file.Recommendations
For D-Link DIR-868L versions DIR868LA1 FW112b04 and earlier, consider disabling access to the
soap.cgi endpoint until a patch is available.
For D-Link DIR-865L versions DIR-865L REVA FIRMWARE PATCH 1.08.B01 and earlier, restrict the use of the Treturn parameter in the soap.cgi endpoint to minimize the risk of exploitation.
For D-Link DIR-860L versions DIR860LA1 FW110b04 and earlier, avoid using the Treturn parameter in the soap.cgi endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-860L
D-Link Dir-865L
D-Link Dir-868L