PT-2024-2136 · D Link · D-Link Gortac750 A1 Fw V101B03
Published
2024-03-04
·
Updated
2025-05-02
·
CVE-2024-27684
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link GORTAC750 A1 FW v101b03
Description
A Cross-site scripting (XSS) vulnerability in components such as
dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi, and seama.cgi allows remote attackers to inject arbitrary web script or HTML via the url parameter. This vulnerability is related to the lack of protection for the web page structure, which can be exploited by a remote attacker to conduct a cross-site scripting attack.Recommendations
For D-Link GORTAC750 A1 FW v101b03, consider disabling access to the vulnerable components
dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi, and seama.cgi until a patch is available. Avoid using the url parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Gortac750 A1 Fw V101B03