CVE-2020-15895: D-Link Dir-816l Firmware

Medium severity, CVSS 6.1. EPSS: 2.8% chance of exploitation in the next 30 days.

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

Affected products

  • D-Link Dir-816l Firmware: version 2.06 only; version 2.06.b09 only

Published 2020-07-22. Last modified 2026-06-17.