Description
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.
In plain language
AI Act nowD-Link DSL-2760U firmware before 1.12 has a flaw attackers have used, so businesses running this gateway should replace or update it now.
Authenticated stored XSS in D-Link DSL-2760U Gateway Rev. E1 management endpoints permits arbitrary script or HTML injection through multiple configuration parameters.
What to do now
- Check whether you use a D-Link DSL-2760U gateway and view its firmware version in the device administration page.
- Upgrade D-Link DSL-2760U firmware to version 1.12 following D-Link's instructions.
- If an update cannot be installed, remove internet access to the administration page and restrict it to trusted staff networks.
- Change gateway administrator passwords and review saved configuration names and fields for unfamiliar entries.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2013-5223 and every CVE in our database. Create a free account — no credit card required.
Create Free Account