CVE-2017-10676
Published Jul 20, 2017On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.
Vendor/product archive
2 CVEs tagged to d-link / dir-600m_firmware — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.
CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified oth…