CVE-2017-10676: XSS
Published Jul 20, 2017
·Updated
On D-Link DIR-600M devices before C1v3.05ENB01beta20170306, XSS was found in the form2userconfig.cgi username parameter.
Affected Software
2 affected components
D-Link Dir-600m Firmware=fw3.05b01
Dlink Dir-600m
Remediation
Event History
Jul 20, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10676?
The severity of CVE-2017-10676 is classified as medium with a score of 6.1.
2
How do I fix CVE-2017-10676?
You can fix CVE-2017-10676 by updating the firmware to version C1_v3.05ENB01_beta_20170306 or later.
3
Which devices are affected by CVE-2017-10676?
The affected devices are D-Link DIR-600M devices running firmware versions prior to C1_v3.05ENB01_beta_20170306.
4
What type of vulnerability is CVE-2017-10676?
CVE-2017-10676 is a stored cross-site scripting (XSS) vulnerability.
5
What impact does CVE-2017-10676 have on affected devices?
CVE-2017-10676 allows an attacker to exploit the XSS vulnerability via the username parameter in form2userconfig.cgi.