Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-5223

80
FAUCET Score

CVE-2013-5223 describes multiple cross-site scripting (XSS) vulnerabilities in the D-Link DSL-2760U Gateway (Rev. E1) firmware. These flaws allow remote authenticated users to inject arbitrary web script or HTML through various parameters across several CGI scripts. The vulnerability has a CVSS score of 5.4 (Medium), indicating a network-based attack requiring low privileges and user interaction, potentially leading to low impact on confidentiality and integrity. This CVE is actively exploited, listed in the KEV catalog, and has a high FAUCET Risk Score of 99/100, with community discussion and media coverage suggesting significant attention, including its association with the "BotenaGo" malware. While no Metasploit or Nuclei exploits are publicly available, similar XSS exploits for D-Link devices exist on ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.12CPE matchmatch criteria
cpe:2.3:o:dlink:dsl-2760u_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
33.57%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 25, 2022
ExploitDB: EDB-36987 · May 11, 2015
This CVE's current EPSS score of 0.3357 is in the 99th percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
osvdb.org / 99603
Broken Link
osvdb.org / 99604
Broken Link
osvdb.org / 99605
Broken Link
osvdb.org / 99606
Broken Link
osvdb.org / 99607
Broken Link
osvdb.org / 99608
Broken Link
osvdb.org / 99609
Broken Link
osvdb.org / 99610
Broken Link
osvdb.org / 99611
Broken Link
osvdb.org / 99612
Broken Link
osvdb.org / 99613
Broken Link
osvdb.org / 99615
Broken Link
osvdb.org / 99616
Broken Link
packetstormsecurity.com / files/123976
ExploitThird Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2013/Nov/76
ExploitMailing ListThird Party Advisory
securityadvisories.dlink.com / security/publication.aspx
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/88723
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/88724
Third Party AdvisoryVDB Entry