First published: Fri Feb 18 2022(Updated: )
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsl-2730e Firmware | =ct-20131125 | |
Dlink DSL-2730E |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46108 is a medium severity vulnerability due to its potential for XSS exploitation.
To fix CVE-2021-46108, update the firmware of your D-Link DSL-2730E device to the latest version.
CVE-2021-46108 affects D-Link DSL-2730E devices running the ct-20131125 firmware version.
CVE-2021-46108 can facilitate cross-site scripting (XSS) attacks through the username parameter.
A temporary workaround for CVE-2021-46108 is to avoid using the affected password page for configuration.