← Back

CVE-2020-25786

nvd nist
Published: Sep 19, 2020Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

Affected (7)

6 products
Dir 803 Firmware
Dir 816l Firmware
Dir 645 Firmware
Dir 815 Firmware
Dir 860l Firmware
Dir 865l Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.04.b02
Running on/withPlatform Versions
Dlink
Dir 803
Version a1
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Dlink
Version 2.06.b09 beta
Version 2.06
Running on/withPlatform Versions
Dlink
Dir 816l
Version b1
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.06b01
Running on/withPlatform Versions
Dlink
Dir 645
Version a1
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.07.b01
Running on/withPlatform Versions
Dlink
Dir 815
Version b1
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.10b04
Running on/withPlatform Versions
Dlink
Dir 860l
Version a1
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.08b01
Running on/withPlatform Versions
Dlink
Dir 865l
Version a1

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.