First published: Sat Aug 25 2018(Updated: )
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-615 | =20.07 | |
D-Link DIR-615 | =t1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-15874 is classified as Medium due to its potential impact on the security and privacy of users.
To fix CVE-2018-15874, update the D-Link DIR-615 router firmware to the latest version or apply any security patches provided by D-Link.
CVE-2018-15874 is classified as a Cross-site scripting (XSS) vulnerability.
CVE-2018-15874 affects the D-Link DIR-615 routers running firmware version 20.07.
Attackers can exploit CVE-2018-15874 by injecting malicious JavaScript into the Active Client Table page via the hostname field in a DHCP request.