vendor:
DIR-615 Wireless Router
by:
Sanyam Chawla
4.8
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: DIR-615 Wireless Router
Affected Version From: T1
Affected Version To: T1
Patch Exists: YES
Related CWE: CVE-2019-19742
CPE: h:dlink:dir-615:20.07
Platforms Tested: Windows 10, Kali Linux
2019
D-Link DIR-615 Wireless Router – Persistent Cross-Site Scripting
The D-Link DIR-615 Wireless Router is vulnerable to persistent cross-site scripting. An attacker can inject malicious script into the name field, which gets saved by the server and is reflected on the user page. This allows the attacker to execute the script and gather sensitive information from the victim, such as IP, cookies, and user agent. Additionally, HTML injection is possible by inserting HTML tags into the username field.
Mitigation:
To mitigate this vulnerability, it is recommended to update the firmware of the D-Link DIR-615 Wireless Router to the latest version. Additionally, input validation should be implemented to sanitize user input and prevent script injection.