CVE-2020-25786

Severity
6.1MEDIUM
EPSS
0.7%
top 28.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateMay 24

Description

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

NVDdlink/dir-816l_firmware2.06, 2.06.b09+1

🔴Vulnerability Details

2
GHSA
GHSA-5x8h-xjj6-w38j: ** UNSUPPORTED WHEN ASSIGNED ** webinc/js/info2022-05-24
CVEList
CVE-2020-25786: webinc/js/info2020-09-19
CVE-2020-25786 (MEDIUM CVSS 6.1) | webinc/js/info.php on D-Link DIR-81 | cvebase.io