CVE-2013-5223
KEVlargeAuthenticated Cross-Site Scripting (XSS) in D-Link DSL-2760U Gateway
CISA: D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
CVE-2013-5223 is a cross-site scripting vulnerability (CWE-79) in the web management interface of the D-Link DSL-2760U gateway, which CISA describes as allowing remote authenticated users to inject arbitrary web script or HTML. An attacker holding valid credentials for the router's administration pages (typically on the LAN, or wherever the admin interface is exposed) inserts crafted script or HTML that then executes in the browsers of other users of that interface. Successful injection can expose or hijack administrative sessions and steal credentials, and can be combined with additional requests to tamper with or reconfigure the device. Only the D-Link DSL-2760U is identified as affected; the available data provides no affected firmware version range. Although no public proof-of-concept is cataloged, CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-25 (ransomware use unknown), confirming exploitation in the wild, and EPSS assigns a 33.6% probability of exploitation within 30 days (98th percentile).
What to do: Per the CISA KEV required action, apply firmware updates per D-Link's instructions; since this data specifies no affected versions, confirm with the vendor whether current DSL-2760U firmware is available and replace end-of-life units that can no longer be updated. As an interim mitigation, restrict the administration interface to the trusted LAN (disable remote/WAN management), use strong admin credentials, and review router logs and configuration for unexpected changes.
| D-Link DSL-2760U | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
- Affected
- D-Link DSL-2760U
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- D-Link
- Products
- DSL-2760U
- Weakness
- CWE-79