CVE-2018-15875: XSS
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15875?
CVE-2018-15875 has a medium severity rating due to its ability to allow cross-site scripting attacks on D-Link DIR-615 routers.
How do I fix CVE-2018-15875?
To fix CVE-2018-15875, update your D-Link DIR-615 firmware to a version that addresses the XSS vulnerability.
What devices are affected by CVE-2018-15875?
CVE-2018-15875 affects D-Link DIR-615 routers running firmware version 20.07.
What type of attack does CVE-2018-15875 enable?
CVE-2018-15875 enables attackers to perform cross-site scripting (XSS) attacks through the router's admin UPnP page.
Can CVE-2018-15875 be exploited remotely?
Yes, CVE-2018-15875 can potentially be exploited remotely, allowing external attackers to inject malicious scripts.