CVE-2017-14415: XSS
Published Sep 13, 2017
·Updated
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.
Affected Software
4 affected components
Dlink Dir-850l Firmware<fw114wwb07_h2ab
Dlink Dir-850l Firmware=fw114wwb07_h2ab-beta1
Dlink DIR-850L
D-Link DIR-850L firmware<=fw114wwb07_h2ab
Event History
Sep 13, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14415?
CVE-2017-14415 is classified as a High severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2017-14415?
To fix CVE-2017-14415, upgrade your D-Link DIR-850L firmware to the latest version beyond FW114WWb07_h2ab.
3
What is the impact of CVE-2017-14415 on my D-Link DIR-850L device?
CVE-2017-14415 allows attackers to execute arbitrary scripts in the user's browser, potentially compromising the confidentiality of users.
4
Which devices are affected by CVE-2017-14415?
CVE-2017-14415 affects D-Link DIR-850L devices with firmware versions through FW114WWb07_h2ab, particularly beta1.
5
What type of vulnerability is CVE-2017-14415?
CVE-2017-14415 is a Cross-Site Scripting (XSS) vulnerability that exploits the action parameter in a specific PHP file.