CVE-2018-6212: D-Link Dir-620 Firmware
Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filtration for special characters in the "Search" field and incorrect processing of the XMLHttpRequest object.
Affected products
- D-Link Dir-620 Firmware: version 1.0.3 only; version 1.0.37 only; version 1.3.1 only; version 1.3.3 only; version 1.3.7 only; version 1.4.0 only; …
Published 2018-06-20. Last modified 2026-06-17.