First published: Sat Aug 25 2018(Updated: )
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-615 | =20.07 | |
D-Link DIR-615 | =t1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15875 has a medium severity rating due to its ability to allow cross-site scripting attacks on D-Link DIR-615 routers.
To fix CVE-2018-15875, update your D-Link DIR-615 firmware to a version that addresses the XSS vulnerability.
CVE-2018-15875 affects D-Link DIR-615 routers running firmware version 20.07.
CVE-2018-15875 enables attackers to perform cross-site scripting (XSS) attacks through the router's admin UPnP page.
Yes, CVE-2018-15875 can potentially be exploited remotely, allowing external attackers to inject malicious scripts.