A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to inject malicious scripts in the device and execute commands via browser that is configuring the unit.
References
Link | Resource |
---|---|
http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10082 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
No history.
Information
Published : 2019-12-30 20:15
Updated : 2020-01-06 19:08
NVD link : CVE-2018-7859
Mitre link : CVE-2018-7859
CVE.ORG link : CVE-2018-7859
JSON object : View
Products Affected
dlink
- dgs-1510-28xmp_firmware
- dgs-1510-52x
- dgs-1510-20_firmware
- dgs-1510-28
- dgs-1510-20
- dgs-1510-28x
- dgs-1510-52_firmware
- dgs-1510-52x_firmware
- dgs-1510-52xmp
- dgs-1510-28xmp
- dgs-1510-28p_firmware
- dgs-1510-52xmp_firmware
- dgs-1510-52
- dgs-1510-28_firmware
- dgs-1510-28p
- dgs-1510-28x_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')