CVE-2017-14414: XSS
Published Sep 13, 2017
·Updated
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/shareport.php.
Affected Software
4 affected components
Dlink Dir-850l Firmware<fw114wwb07_h2ab
Dlink Dir-850l Firmware=fw114wwb07_h2ab-beta1
Dlink DIR-850L
D-Link DIR-850L firmware<=fw114wwb07_h2ab
Event History
Sep 13, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14414?
The severity of CVE-2017-14414 is considered moderate due to the potential for exploitation via cross-site scripting (XSS).
2
How do I fix CVE-2017-14414?
To fix CVE-2017-14414, update the D-Link DIR-850L firmware to a version later than FW114WWb07_h2ab_beta1.
3
What devices are affected by CVE-2017-14414?
CVE-2017-14414 affects D-Link DIR-850L devices running firmware up to FW114WWb07_h2ab_beta1.
4
What type of vulnerability is CVE-2017-14414?
CVE-2017-14414 is a cross-site scripting (XSS) vulnerability found in the action parameter of a specific script on D-Link devices.
5
Can CVE-2017-14414 be exploited remotely?
Yes, CVE-2017-14414 can potentially be exploited remotely if the device is accessible over the internet.