CVE-2020-25786: D-Link DIR-645 Firmware
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header
Affected products
- D-Link DIR-645 Firmware: version 1.06b01 only
- D-Link Dir-803 Firmware: version 1.04.b02 only
- D-Link Dir-815 Firmware: version 2.07.b01 only
- D-Link Dir-816l Firmware: version 2.06 only; version 2.06.b09 only
- D-Link Dir-860l Firmware: version 1.10b04 only
- D-Link Dir-865l Firmware: version 1.08b01 only
Published 2020-09-19. Last modified 2026-06-17.