PT-2023-3552 · D Link · D-Link Di-7500G-Ci

Hashshfza

·

Published

2023-06-04

·

Updated

2025-01-06

·

CVE-2023-34856

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions D-Link DI-7500G-CI version 19.05.29A
Description A Cross Site Scripting (XSS) issue allows attackers to execute arbitrary code by uploading a crafted HTML file to the "interface /auth pic.cgi". The vulnerability is related to the lack of protection measures for the web page structure, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations For D-Link DI-7500G-CI version 19.05.29A, consider disabling access to the /auth pic.cgi interface until a patch is available to prevent exploitation. Avoid uploading HTML files to this interface until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03769
CVE-2023-34856

Affected Products

D-Link Di-7500G-Ci