CVE-2016-10699: D-Link DSL-2740e Firmware

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a remote unauthenticated user may craft logins and passwords with script tags in them. Because there is no sanitization in the input fields, an unaware logged-in administrator may be a victim when checking the router logs.

Affected products

  • D-Link DSL-2740e Firmware: version 1.00_bg_20150720 only

Published 2017-10-31. Last modified 2026-06-17.