Vulnerability Description
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dsl-3782 Firmware | 1.01 |
| Dlink | Dsl-3782 | - |
Related Weaknesses (CWE)
References
- https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-anExploitThird Party Advisory
- https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-anExploitThird Party Advisory
FAQ
What is CVE-2018-17989?
CVE-2018-17989 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The...
How severe is CVE-2018-17989?
CVE-2018-17989 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17989?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dsl-3782 Firmware, Dlink Dsl-3782.