CVE-2018-7859

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/12/2019
Last modified:
06/01/2020

Description

A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to inject malicious scripts in the device and execute commands via browser that is configuring the unit.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dgs-1510-20_firmware:*:*:*:*:*:*:*:* 1.31.b003 (including)
cpe:2.3:o:dlink:dgs-1510-20_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-20_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-20:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28_firmware:*:*:*:*:*:*:*:* 1.31.b003 (including)
cpe:2.3:o:dlink:dgs-1510-28_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-28:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28p_firmware:*:*:*:*:*:*:*:* 1.31.b003 (including)
cpe:2.3:o:dlink:dgs-1510-28p_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28p_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-28p:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28x_firmware:*:*:*:*:*:*:*:* 1.31.b003 (including)
cpe:2.3:o:dlink:dgs-1510-28x_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28x_firmware:1.30.007:*:*:*:*:*:*:*