CVE-2018-7859

A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to inject malicious scripts in the device and execute commands via browser that is configuring the unit.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-20_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-20_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-20:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-28_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-28:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-28p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28p_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28p_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-28p:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-28x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28x_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28x_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-28x:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-28xmp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28xmp_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-28xmp_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-28xmp:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-52x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-52x_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-52x_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-52x:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-52xmp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-52xmp_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-52xmp_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-52xmp:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:dlink:dgs-1510-52_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-52_firmware:1.20.011:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dgs-1510-52_firmware:1.30.007:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dgs-1510-52:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:12

Type Values Removed Values Added
References () http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10082 - Vendor Advisory () http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10082 - Vendor Advisory

Information

Published : 2019-12-30 20:15

Updated : 2024-11-21 04:12


NVD link : CVE-2018-7859

Mitre link : CVE-2018-7859

CVE.ORG link : CVE-2018-7859


JSON object : View

Products Affected

dlink

  • dgs-1510-28p_firmware
  • dgs-1510-28x_firmware
  • dgs-1510-52x
  • dgs-1510-28xmp_firmware
  • dgs-1510-20
  • dgs-1510-52xmp_firmware
  • dgs-1510-28_firmware
  • dgs-1510-28
  • dgs-1510-28x
  • dgs-1510-52xmp
  • dgs-1510-28xmp
  • dgs-1510-28p
  • dgs-1510-52_firmware
  • dgs-1510-20_firmware
  • dgs-1510-52
  • dgs-1510-52x_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')