CVE-2013-5223
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Base score: 5.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 51%
- Percentile among all scored CVEs: 99
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 3/25/2022
- Remediation due date: 4/15/2022
- Known ransomware use: Unknown
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · D-Link DSL-500B Gen 2 - Parental Control Configuration Panel Persistent Cross-Site Scripting (5/11/2015)
- Published on Exploit-DB · D-Link DSL-500B Gen 2 - URL Filter Configuration Panel Persistent Cross-Site Scripting (5/11/2015)
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1189Drive-by Compromiseinitial access75 % - Primary impact
T1059.007JavaScriptexecution65 % - Secondary impact
T1565.001Stored Data Manipulationimpact60 %
XSS almacenado en múltiples parámetros de interfaz web (CWE-79) permite inyección de script arbitrario. Vector AV:N/PR:L/UI:R indica acceso remoto autenticado con interacción. Afecta router D-Link vulnerable a drive-by scripting.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-79
- CWE-79
References
- http://osvdb.org/99603
- http://osvdb.org/99604
- http://osvdb.org/99605
- http://osvdb.org/99606
- http://osvdb.org/99607
- http://osvdb.org/99608
- http://osvdb.org/99609
- http://osvdb.org/99610
- http://osvdb.org/99611
- http://osvdb.org/99612
- http://osvdb.org/99613
- http://osvdb.org/99615
- http://osvdb.org/99616
- http://packetstormsecurity.com/files/123976
- http://seclists.org/fulldisclosure/2013/Nov/76
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88723
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88724
- http://osvdb.org/99603
- http://osvdb.org/99604
- http://osvdb.org/99605
- http://osvdb.org/99606
- http://osvdb.org/99607
- http://osvdb.org/99608
- http://osvdb.org/99609
- http://osvdb.org/99610
- http://osvdb.org/99611
- http://osvdb.org/99612
- http://osvdb.org/99613
- http://osvdb.org/99615
- http://osvdb.org/99616
- http://packetstormsecurity.com/files/123976
- http://seclists.org/fulldisclosure/2013/Nov/76
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10002
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88723
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88724
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-5223
Raw JSON (NVD)
Show
{
"id": "CVE-2013-5223",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2013-5223",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-07T14:11:58.190782Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-11-19T04:50:12.063",
"references": [
{
"url": "http://osvdb.org/99603",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99604",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99605",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99606",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99607",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99608",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99609",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99610",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99611",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99612",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99613",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99615",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99616",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/123976",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2013/Nov/76",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10002",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/88723",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/88724",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/99603",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99604",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99605",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99606",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99607",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99608",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99609",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99610",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99611",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99612",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99613",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99615",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/99616",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/123976",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2013/Nov/76",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10002",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/88723",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/88724",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-5223",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de XSS en D-Link DSL-2760U Gateway (Rev. E1) permite a usuarios remotos autenticados inyectar script web o HTML a través de (1) parámetro ntpServer1 a sntpcfg.cgi, parámetro username a (2) ddnsmngr.cmd o (3) todmngr.tod, (4) parámetro TodUrlAdd a urlfilter.cmd, (5) parámetro appName a scprttrg.cmd, (6) fitName en una acción add o (7) parámetro rmLst en una acción remove a scoutfit.cmd, (8) parámetro groupName a portmapcfg.cmd, (9) parámetro snmpRoCommunity a snmpconfig.cgi, (10) parámetro fitName a scinfit.cmd, (11) PolicyName en una acción add o (12) parámetro rmLst en una acción remove a prmngr.cmd, (13) parámetro ippName a ippcfg.cmd, (14) smbNetBiosName o (15) parámetro smbDirName a samba.cgi, o (16) parámetro wISsid a wicfg.wi."
}
],
"lastModified": "2026-06-16T23:58:32.217",
"cisaActionDue": "2022-04-15",
"cisaExploitAdd": "2022-03-25",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dlink:dsl-2760u_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6898225-0F82-4BF7-9601-C979B12FED23",
"versionEndExcluding": "1.12"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:dlink:dsl-2760u:e1:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CA475707-6991-4344-8FFF-36FA7AC0F23E"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability"
}