LiveActive security incident?Get immediate response
CVE Record

CVE-2018-17989: A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that a...

A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2018-17989 is a stored cross-site scripting issue in the D-Link DSL-3782 web interface, firmware 1.01. An authenticated attacker can save malicious HTML or JavaScript in the ACL page, causing it to run when a user later opens that page. The sources do not provide CVSS, vendor fix details, or evidence of active exploitation.

Executive priority

Treat this as a targeted administrative-interface risk, not a confirmed internet-scale emergency. Prioritize identifying affected routers, limiting management access, and confirming whether vendor-supported firmware or replacement is available.

Technical view

The vulnerability affects the ACL page in the device web UI. The CVE states that injected JavaScript or HTML executes when /cgi-bin/New_GUI/Acl.asp is requested. Successful use requires authenticated access to the interface. Product naming should be verified because the CVE says DSL-3782 while the linked advisory URL references DIR-3782.

Likely exposure

Exposure is likely limited to D-Link DSL-3782 firmware 1.01 devices where authenticated users can reach the management web interface. Risk increases if router administration is shared broadly, accessible from untrusted networks, or used from privileged administrator browsers.

Exploitation context

No source in the bundle states active exploitation, KEV listing, public weaponization, or unauthenticated exploitability. The known prerequisite is authenticated web-interface access. Impact would center on browser-side execution in a user session that views the affected ACL page.

Researcher notes

Evidence is sparse: no CVSS vector, CWE mapping, exploit status, or official patch information is included. The authenticated stored XSS behavior and affected firmware come from the CVE description and linked advisory. Verify product naming before asset matching.

Mitigation direction

  • Check D-Link guidance for firmware updates or official mitigation advice.
  • Restrict router management access to trusted administrators and trusted networks.
  • Disable remote administration if not explicitly required.
  • Replace or retire devices that cannot be updated safely.
  • Avoid using privileged browsing sessions for routine router administration.

Validation and detection

  • Inventory D-Link DSL-3782 devices and confirm firmware version 1.01 exposure.
  • Confirm whether /cgi-bin/New_GUI/Acl.asp is reachable only by trusted administrators.
  • Review router administration accounts for unnecessary or shared access.
  • Check vendor advisories for corrected firmware or lifecycle status.
  • Look for stored unexpected HTML or script content in ACL configuration fields.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-17989 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.