Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the file upload feature of the VPN configuration module.
References
Link | Resource |
---|---|
https://github.com/Mrnmap/mrnmap-cve | Third Party Advisory |
https://github.com/Mrnmap/mrnmap-cve/blob/main/CVE-2024-28730-ReflectedXSS | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-11-12 23:15
Updated : 2024-11-22 15:07
NVD link : CVE-2024-28730
Mitre link : CVE-2024-28730
CVE.ORG link : CVE-2024-28730
JSON object : View
Products Affected
dlink
- dwr-2000m_firmware
- dwr-2000m
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')