CVE-2020-15895 is a Cross-Site Scripting (XSS) vulnerability affecting D-Link DIR-816L devices running firmware versions 2.x before 1.10b04Beta02. The flaw stems from a lack of output filtration for the RESULT parameter in the webinc/js/info.php file, allowing malicious script injection. Rated 6.1 MEDIUM, this vulnerability can be exploited remotely with low attack complexity, potentially leading to information disclosure and integrity compromise. While not listed on CISA's KEV catalog, Nuclei templates exist for detection, and it has garnered some community and media attention, including a BleepingComputer article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.06CPE matchmatch criteria | cpe:2.3:o:dlink:dir-816l_firmware:2.06:*:*:*:*:*:*:* | ||
2.06.b09CPE matchmatch criteria | cpe:2.3:o:dlink:dir-816l_firmware:2.06.b09:beta:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.