DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service for HTTP, even though a TCP relay service for HTTPS is also established.
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/wpsacts.php.
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/shareport.php.
D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.
The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07h2abbeta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.