Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34856


A Cross Site Scripting (XSS) vulnerability in D-Link DI-7500G-CI-19.05.29A allows attackers to execute arbitrary code via uploading a crafted HTML file to the interface /auth_pic.cgi.


Published

2023-06-09T20:15:10.277

Last Modified

2025-01-06T19:15:12.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink di-7500g-ci_firmware 19.05.29a Yes
Hardware dlink di-7500g-ci - No

References