CVE-2019-13374: D-Link Central Wifimanager

Medium severity, CVSS 6.1. EPSS: 2.4% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

Affected products

  • D-Link Central Wifimanager: version 1.03 only

Published 2019-07-06. Last modified 2026-06-17.