VulnerabilityAnalyzed
CVE-2026-7026
A vulnerability was determined in D-Link DGS-3420 1.50.018.
MEDIUM 5.4EPSS 0.56%
Does this matter?
Lower severity and a low EPSS score (0.56%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
- CVSS 4.0
- 5.4 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- dlink/dgs-3420-28tc firmware
- Source
- cna@vuldb.com
References
- https://vuldb.com/submit/797877Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/359606Third Party Advisory, VDB Entry
- https://vuldb.com/vuln/359606/ctiPermissions Required, VDB Entry
- https://www.dlink.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.