First published: Sat Sep 19 2020(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-803 Firmware | =1.04.b02 | |
Dlink Dir-803 | =a1 | |
Dlink Dir-816l Firmware | =2.06 | |
Dlink Dir-816l Firmware | =2.06.b09-beta | |
Dlink Dir-816l | =b1 | |
Dlink Dir-645 Firmware | =1.06b01 | |
Dlink Dir-645 | =a1 | |
Dlink Dir-815 Firmware | =2.07.b01 | |
Dlink Dir-815 | =b1 | |
Dlink Dir-860l Firmware | =1.10b04 | |
Dlink Dir-860l | =a1 | |
Dlink Dir-865l Firmware | =1.08b01 | |
Dlink Dir-865l | =a1 | |
All of | ||
Dlink Dir-803 Firmware | =1.04.b02 | |
Dlink Dir-803 | =a1 | |
All of | ||
Any of | ||
Dlink Dir-816l Firmware | =2.06 | |
Dlink Dir-816l Firmware | =2.06.b09-beta | |
Dlink Dir-816l | =b1 | |
All of | ||
Dlink Dir-645 Firmware | =1.06b01 | |
Dlink Dir-645 | =a1 | |
All of | ||
Dlink Dir-815 Firmware | =2.07.b01 | |
Dlink Dir-815 | =b1 | |
All of | ||
Dlink Dir-860l Firmware | =1.10b04 | |
Dlink Dir-860l | =a1 | |
All of | ||
Dlink Dir-865l Firmware | =1.08b01 | |
Dlink Dir-865l | =a1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25786 is a vulnerability that allows XSS (Cross-Site Scripting) attacks via the HTTP Referer header on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices.
CVE-2020-25786 has a severity level of 6.1, which is considered medium.
CVE-2020-25786 affects D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices.
You can exploit CVE-2020-25786 by sending a specially crafted HTTP Referer header to the vulnerable device.
To mitigate CVE-2020-25786, it is recommended to upgrade to a supported firmware version provided by the maintainer.