CVE-2018-17989: XSS
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/NewGUI/Acl.asp" is requested.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17989?
CVE-2018-17989 is a stored XSS vulnerability in the web interface on D-Link DSL-3782 devices with firmware 1.01.
How can an attacker exploit CVE-2018-17989?
An authenticated attacker can inject a JavaScript or HTML payload inside the ACL page and execute it in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
What is the severity of CVE-2018-17989?
The severity of CVE-2018-17989 is medium (5.4).
Which devices are affected by CVE-2018-17989?
D-Link DSL-3782 devices with firmware 1.01 are affected by CVE-2018-17989.
Is D-Link DSL-3782 vulnerable to CVE-2018-17989?
Yes, D-Link DSL-3782 devices with firmware 1.01 are vulnerable to CVE-2018-17989.