CVE-2024-28436
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.
Published 2024-04-22. Last modified 2026-06-17.