D-Link DIR-816
cpe:2.3:h:d-link:dir-816:*:*:*:*:*:*:*, +12 more
- 1.01TO
A cross-site scripting (XSS) vulnerability has been identified in the D-Link DIR-816 router running firmware version 1.01TO. The issue arises in the 'cgi-bin/webproc' directory, specifically within the 'Setup' menu. The vulnerability allows remote attackers to inject malicious scripts through the 'SSID' parameter, which are then executed without proper validation. This flaw could be exploited to steal sensitive information from users.
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.
To reproduce this vulnerability, access the router's web interface and navigate to the '24G_basic' page under the '24gwlan' menu. Inject a script into the 'SSID' parameter, which will be executed as cross-site scripting.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.