CVE-2013-5223 describes multiple cross-site scripting (XSS) vulnerabilities in the D-Link DSL-2760U Gateway (Rev. E1) firmware. These flaws allow remote authenticated users to inject arbitrary web script or HTML through various parameters across several CGI scripts. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack requiring low privileges and user interaction, potentially leading to low impact on confidentiality and integrity. This CVE is actively exploited, listed in the KEV catalog, and has a high FAUCET Risk Score of 99/100, with community discussion and media coverage suggesting significant attention, including its association with the "BotenaGo" malware. While no Metasploit or Nuclei exploits are publicly available, similar XSS exploits for D-Link devices exist on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12CPE matchmatch criteria | cpe:2.3:o:dlink:dsl-2760u_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.