CVE-2026-7026
בינונית 4.8
תיאור (מקור, אנגלית)
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
מדדים
- CVSS 3.1
-
4.8 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N - CVSS 4.0
-
5.4 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-26/9/2026
- CWE
- CWE-79, CWE-94
מוצרים מושפעים
dlink: dgs-3420-28tc firmware; dlink: dgs-3420-28tc
קישורים
- https://vuldb.com/submit/797877 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359606 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/359606/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product