CVE-2018-17989
MEDIUMD-Link DSL-3782 Firmware 1.01 - Authenticated Stored Cross-Site Scripting in ACL Page
Title source: llmDescription
A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/
Scores
CVSS v3
5.4
EPSS
0.0009
EPSS Percentile
25.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
dlink/dsl-3782_firmware
1.01
Published
Apr 01, 2019
Tracked Since
Feb 18, 2026