CVE-2019-13562

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/07/2019
Last modified:
12/07/2019

Description

D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-655_firmware:3.02b05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-655:-:*:*:*:*:*:*:*