CVE-2017-10676: D-Link Dir-600m Firmware
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.
Affected products
- D-Link Dir-600m Firmware: version fw3.05b01 only
Published 2017-07-20. Last modified 2026-06-17.