CVE-2020-25786 - CVE House
Back to Database
Status published Medium CVE-2020-25786

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows...

Vulnerability Description

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-25786

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

dir-803 firmware, dir-816l firmware, dir-645 firmware, dir-815 firmware, dir-860l firmware, dir-865l firmware
Vulnerable Versions:
1.04.b02, 2.06, 2.06.b09, 1.06b01, 2.07.b01, 1.10b04, 1.08b01

Timeline

Official Publish: September 19th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.