CVE Feed

    Dashboard / CVE / CVE-2016-10699

    CVE-2016-10699

    D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a remote unauthenticated user may craft logins and passwords with script tags in them. Because there is no sanitization in the input fields, an unaware logged-in administrator may be a victim when checking the router logs.

    Published:Oct 31, 2017
    Last Modified:Apr 20, 2025
    EPS:Oct 31, 2017
    EPSS Score:0.00346
    CVSS Score:6.1

    Affected Products

    Vendor
    Dlink
    Product
    Dsl-2740e
    Vendor
    Dlink
    Product
    Dsl-2740e Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High