CVE-2018-17441: D-Link Central Wifimanager

Medium severity, CVSS 6.1. EPSS: 5.7% chance of exploitation in the next 30 days.

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.

Affected products

  • D-Link Central Wifimanager: from 1.00, up to and including 1.03

Published 2018-10-08. Last modified 2026-06-17.