← Back

CVE-2024-28730

nvd nist
Published: Nov 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the file upload feature of the VPN configuration module.

Affected (1)

1 product
Dwr 2000m Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.34me
Running on/withPlatform Versions
Dlink
Dwr 2000m
All versions

References (2)

Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.