PT-2018-4010 · D Link · D-Link Dir-600M C1
Prasenjit Kanti Paul
·
Published
2018-02-12
·
Updated
2023-04-26
·
CVE-2018-6936
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-600M C1 version 3.01
Description
The issue exists due to inadequate protection of the web page structure in the administrative panel of the D-Link DIR-600M C1 Wi-Fi router's firmware. This allows a remote attacker to conduct a cross-site scripting (XSS) attack. The attack can be performed via the SSID or the name of a user account.
Recommendations
For D-Link DIR-600M C1 version 3.01, consider restricting access to the administrative panel until a patch is available. As a temporary workaround, avoid using user-supplied input in the SSID or user account name fields to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dir-600M C1