Impact
The vulnerability resides in the sp_pppoe_user.js script of the D‑Link DSL‑6641K firmware N8.TR069.20131126. Manipulation of the Username field in the doSubmitPPP function allows an attacker to inject arbitrary script payloads that are executed in the browser context of authenticated users. The injected code can deface web pages, steal session cookies or redirect users to malicious sites. The issue is identified as CWE‑79 (XSS) and CWE‑94 (code injection).
Affected Systems
Affected device is the D‑Link DSL‑6641K with firmware version N8.TR069.20131126. The product is no longer supported by the manufacturer, and no official patch is available. Consequently the risk applies only to existing units still deployed.
Risk and Exploitability
The CVSS base score is 4.8, indicating moderate risk, while the EPSS is below 1 % suggesting a low likelihood of widespread exploitation; however, the exploit is publicly known and can be launched remotely via the web interface. Because no patch exists, an organization must rely on isolation or replacement to mitigate the risk.
OpenCVE Enrichment