CVE-2017-14416: XSS
Published Sep 13, 2017
·Updated
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.
Affected Software
4 affected components
Dlink Dir-850l Firmware<fw114wwb07_h2ab
Dlink Dir-850l Firmware=fw114wwb07_h2ab-beta1
Dlink DIR-850L
D-Link DIR-850L firmware<=fw114wwb07_h2ab
Event History
Sep 13, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14416?
CVE-2017-14416 is classified as a medium severity vulnerability due to its XSS nature.
2
How do I fix CVE-2017-14416?
To fix CVE-2017-14416, update the D-Link DIR-850L firmware to a version beyond FW114WWb07_h2ab.
3
What type of vulnerability is CVE-2017-14416?
CVE-2017-14416 is a Cross-Site Scripting (XSS) vulnerability affecting specific D-Link router firmware.
4
Which devices are affected by CVE-2017-14416?
The D-Link DIR-850L REV. A with firmware up to FW114WWb07_h2ab is affected by CVE-2017-14416.
5
What is the impact of CVE-2017-14416 on users?
The impact of CVE-2017-14416 includes potential unauthorized access and manipulation of user session data through XSS.