vendor:
DSL-2730B Modem
by:
Mauricio Correa
7.5
CVSS
HIGH
XSS Injection
CWE
Product Name: DSL-2730B Modem
Affected Version From: GE 1.01
Affected Version To: GE 1.01
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 8, Linux
2015
D-Link DSL-2730B Modem wlsecrefresh.wl & wlsecurity.wl Exploit XSS Injection Stored
This exploit allows an attacker to inject malicious code into the wlsecrefresh.wl file of the D-Link DSL-2730B modem. The injected code will be executed in the browser of internal network users, forcing the administrator of the device to reconfigure the modem. Use with caution and at your own risk.
Mitigation:
Apply the latest firmware update provided by D-Link to fix the vulnerability.