CVE-2018-15875

MEDIUM

Dlink Dir-615 Firmware - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 53.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
dlink/dir-615_firmware 20.07
Published Aug 25, 2018
Tracked Since Feb 18, 2026