CVE-2018-6528: XSS
XSS vulnerability in htdocs/webinc/body/bscsmssend.php in D-Link DIR-868L DIR868LA1FW112b04 and previous versions, DIR-865L DIR-865LREVAFIRMWAREPATCH1.08.B01 and previous versions, and DIR-860L DIR860LA1FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to soap.cgi.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DIR-868L (DIR868LA1_FW112b04)to a version that resolves this vulnerability.Fixed in DIR868LA1_FW112b04 - Upgrade
Upgrade
D-Link DIR-865L (DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01)to a version that resolves this vulnerability.Fixed in DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 - Upgrade
Upgrade
D-Link DIR-860L (DIR860LA1_FW110b04)to a version that resolves this vulnerability.Fixed in DIR860LA1_FW110b04 - Compensating control
Mitigate XSS/cookie exposure by preventing untrusted clients from accessing soap.cgi/receiver parameter (e.g., restrict access to the device endpoints at the network layer so only trusted sources can reach soap.cgi).
Event History
Frequently Asked Questions
What is CVE-2018-6528?
CVE-2018-6528 is a Cross-Site Scripting (XSS) vulnerability in D-Link DIR-868L, DIR-865L, and DIR-860L routers.
How does CVE-2018-6528 affect D-Link DIR-868L?
CVE-2018-6528 allows remote attackers to read a cookie via a crafted request to htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L routers running DIR868LA1_FW112b04 and previous versions.
How does CVE-2018-6528 affect D-Link DIR-865L?
CVE-2018-6528 allows remote attackers to read a cookie via a crafted request to htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-865L routers running DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions.
How does CVE-2018-6528 affect D-Link DIR-860L?
CVE-2018-6528 allows remote attackers to read a cookie via a crafted request to htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-860L routers running DIR860LA1_FW110b04 and previous versions.
How can I fix CVE-2018-6528?
To mitigate CVE-2018-6528, users should upgrade to the latest firmware version provided by D-Link.