CVE-2013-6786: XSS

Published Jan 16, 2014
·
Updated

Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.

Affected Software

7 affected components
AllegroSoft RomPager<=4.07
Dlink Dsl-2640r
Dlink Dsl-2641r
Huawei MT882
Sitecom WL-174
TP-Link TD-8816
Zyxel P-660hw D1

Event History

Jan 16, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-6786?

The severity of CVE-2013-6786 is classified as medium due to the potential for unauthorized access and data injection.

2

How do I fix CVE-2013-6786?

To fix CVE-2013-6786, update Allegro RomPager to version 4.51 or later and ensure proper input validation is implemented.

3

What does CVE-2013-6786 exploit?

CVE-2013-6786 exploits a cross-site scripting vulnerability by bypassing the 'forbidden author header' protection mechanism.

4

Which devices are affected by CVE-2013-6786?

Devices affected by CVE-2013-6786 include the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R.

5

Can CVE-2013-6786 be remotely exploited?

Yes, CVE-2013-6786 can be remotely exploited by attackers to inject arbitrary scripts into affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203