CVE-2018-6528 describes a Cross-Site Scripting (XSS) vulnerability in D-Link DIR-868L, DIR-865L, and DIR-860L routers, specifically within the htdocs/webinc/body/bsc_sms_send.php component. An unauthenticated remote attacker can exploit this by crafting a malicious receiver parameter sent to soap.cgi, leading to the theft of cookies. This vulnerability carries a CVSS v3.1 score of 6.1 (Medium), indicating a low attack complexity and the potential for limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= a1_fw110b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-860l_firmware:*:*:*:*:*:*:*:* | ||
<= reva_firmware_patch_1.08.b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-865l_firmware:*:*:*:*:*:*:*:* | ||
<= a1_fw112b04CPE matchmatch criteria | cpe:2.3:o:dlink:dir-868l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.