First published: Wed Jun 30 2004(Updated: )
Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DI-704P | =2.60b2 | |
D-Link DI-614+ | =2.30 | |
D-Link DI-624 | <=1.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0615 is classified as a medium severity vulnerability due to the possibility of remote code execution via cross-site scripting.
To fix CVE-2004-0615, update the firmware of affected D-Link routers to the latest version provided by the manufacturer.
CVE-2004-0615 affects the D-Link DI-614+ with firmware version 2.30, DI-704 with firmware version 2.60B2, and DI-624 routers.
CVE-2004-0615 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.
Yes, CVE-2004-0615 can compromise network security by allowing attackers to perform malicious actions on affected routers.