CVE-2024-28436: XSS
Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the sessionlogin.php component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28436?
CVE-2024-28436 is classified as a high severity cross site scripting vulnerability.
How do I fix CVE-2024-28436?
To fix CVE-2024-28436, upgrade to the latest firmware provided by D-Link for your affected DAP product.
Which D-Link products are affected by CVE-2024-28436?
D-Link DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, and DAP-3662 are all affected by CVE-2024-28436.
What type of attack can be executed through CVE-2024-28436?
CVE-2024-28436 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.
Is there a publicly available exploit for CVE-2024-28436?
As of now, details on publicly accessible exploits for CVE-2024-28436 have not been disclosed.