CVE-2017-10676: D-Link Dir-600m Firmware

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.

Affected products

  • D-Link Dir-600m Firmware: version fw3.05b01 only

Published 2017-07-20. Last modified 2026-06-17.