CVE-2018-6529: XSS
XSS vulnerability in htdocs/webinc/js/bscsmsinbox.php in D-Link DIR-868L DIR868LA1FW112b04 and previous versions, DIR-865L DIR-865LREVAFIRMWAREPATCH1.08.B01 and previous versions, and DIR-860L DIR860LA1FW110b04 and previous versions allows remote attackers to read a cookie via a crafted Treturn parameter to soap.cgi.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-6529?
CVE-2018-6529 is a XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions.
How does CVE-2018-6529 affect D-Link DIR-868L?
CVE-2018-6529 allows remote attackers to read a cookie via a crafted Tret message.
How severe is CVE-2018-6529 vulnerability?
CVE-2018-6529 has a severity score of 6.1, which is considered medium.
How can I fix CVE-2018-6529 vulnerability?
To fix CVE-2018-6529, update your D-Link DIR-868L firmware to version DIR868LA1_FW112b04 or newer.
Where can I find more information about CVE-2018-6529?
More information about CVE-2018-6529 can be found at https://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-proto.