CVE-2018-15874: XSS
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15874?
The severity of CVE-2018-15874 is classified as Medium due to its potential impact on the security and privacy of users.
How do I fix CVE-2018-15874?
To fix CVE-2018-15874, update the D-Link DIR-615 router firmware to the latest version or apply any security patches provided by D-Link.
What type of vulnerability is CVE-2018-15874?
CVE-2018-15874 is classified as a Cross-site scripting (XSS) vulnerability.
Which devices are affected by CVE-2018-15874?
CVE-2018-15874 affects the D-Link DIR-615 routers running firmware version 20.07.
How can attackers exploit CVE-2018-15874?
Attackers can exploit CVE-2018-15874 by injecting malicious JavaScript into the Active Client Table page via the hostname field in a DHCP request.