vendor:
DIR-635
by:
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: DIR-635
Affected Version From: 2.34EU
Affected Version To: 2.34EU
Patch Exists: NO
Related CWE:
CPE: cpe:2.3:h:d-link:dir-635_firmware:2.34eu
Platforms Tested:
Stored XSS in D-Link DIR-635 Router
Injecting scripts into the parameter config.wireless%5B0%5D.ssid_profiles%5B0%5D.ssid reveals that this parameter is not properly validated for malicious input. You need to be authenticated or you have to find other methods for inserting the malicious JavaScript code.
Mitigation:
Properly validate and sanitize user input to prevent XSS attacks.