Severity
5.1MEDIUMNVD
EPSS
1.8%
top 17.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateOct 20

Description

A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. The manipulation of the argument SSID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5d-link/dir-8161.01TO

🔴Vulnerability Details

6
GHSA
NetBird VPN does not remove the default password of an admin account2025-10-20
GHSA
Default Credentials in nginx-defender Configuration Files2025-08-19
GHSA
NodeJS version of the HAX CMS application is distributed with Default Secrets2025-07-21
GHSA
File Browser vulnerable to insecure password handling2025-06-30
GHSA
GHSA-8pp4-8qq6-hjcg: A vulnerability has been found in D-Link DIR-816 12025-02-17
CVE-2025-1392 — Cross-site Scripting in D-link Dir-816 | cvebase