CVE-2019-17663
Published Oct 16, 2019D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.
Vendor/product archive
2 CVEs tagged to dlink / dir-866l — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a…