Vulnerability Description
XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to soap.cgi.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-860L Firmware | <= a1_fw110b04 |
| Dlink | Dir-860L | - |
| Dlink | Dir-865L Firmware | <= reva_firmware_patch_1.08.b01 |
| Dlink | Dir-865L | - |
| Dlink | Dir-868L Firmware | <= a1_fw112b04 |
| Dlink | Dir-868L | - |
Related Weaknesses (CWE)
References
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-865L/REVA/DIR-865L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- https://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-protoExploitThird Party Advisory
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-860L/REVA/DIR-860L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://FTP2.DLINK.COM/SECURITY_ADVISEMENTS/DIR-868L/REVA/DIR-868L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-865L/REVA/DIR-865L_REVA_FIRMWARE_PRelease NotesVendor Advisory
- https://github.com/TheBeeMan/Pwning-multiple-dlink-router-via-SOAP-protoExploitThird Party Advisory
FAQ
What is CVE-2018-6528?
CVE-2018-6528 is a vulnerability with a CVSS score of 6.1 (MEDIUM). XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L...
How severe is CVE-2018-6528?
CVE-2018-6528 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6528?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dir-860L Firmware, Dlink Dir-860L, Dlink Dir-865L Firmware, Dlink Dir-865L, Dlink Dir-868L Firmware.