First published: Thu Jul 11 2019(Updated: )
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-655 Firmware | =3.02b05 | |
Dlink Dir-655 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13562 is a vulnerability in D-Link DIR-655 C devices before 3.02B05 BETA03 that allows cross-site scripting (XSS) attacks.
CVE-2019-13562 affects D-Link DIR-655 C devices before 3.02B05 BETA03 by enabling XSS attacks through specific parameters.
CVE-2019-13562 has a severity rating of 6.1 (medium).
To fix CVE-2019-13562, you should update your D-Link DIR-655 C device firmware to version 3.02B05 BETA03 or later.
You can find more information about CVE-2019-13562 at the following references: [Link 1](https://www.nccgroup.trust/contentassets/7188fe7f130846ffa31827fc1661d120/crosssitescripting.txt) and [Link 2](https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2019/july/the-d-link-dir-655c-from-nothing-to-rce/).