Vulnerability record · CVE-2013-5223 · published 19 November 2013
CVE-2013-5223: D-Link DSL-2760U Gateway stored XSS in multiple CGI parameters
Dlink · Dsl 2760u Firmware
The D-Link DSL-2760U Gateway (Rev. E1) fails to sanitize numerous configuration parameters across its web management CGIs, allowing injection of arbitrary script or HTML. Sixteen distinct parameters are affected, so the flaw is broad rather than isolated to one page. Because the router's admin interface is the target, successful exploitation can compromise the session of anyone who views the injected content.
Description
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable, has public exploit code, and is on CISA KEV with a high EPSS percentile, though it requires an authenticated session and victim interaction, which caps it below critical.
What it is
The D-Link DSL-2760U Gateway (Rev. E1) fails to sanitize numerous configuration parameters across its web management CGIs, allowing injection of arbitrary script or HTML. Sixteen distinct parameters are affected, so the flaw is broad rather than isolated to one page. Because the router's admin interface is the target, successful exploitation can compromise the session of anyone who views the injected content.
Impact
An attacker with an authenticated session can inject script that executes in the browser context of other users viewing the affected pages, enabling session theft or administrative actions performed as the victim. The scope change in the CVSS vector reflects that the injected content can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through the router's web management interface; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), meaning the attacker must already hold an authenticated session and a victim must view the crafted page or parameter.
Exploitation
CVE-2013-5223 is listed in CISA KEV with a 2022-03-25 addition and 2022-04-15 due date, and EPSS shows a 30-day probability of 0.336 (98.3rd percentile). Public exploit references exist (Packet Storm and Full Disclosure), though no ransomware campaign use is documented.
What to do
- Apply the vendor update referenced in D-Link security advisory SAP10002; if no fixed firmware exists for the device, replace or retire it.
- Restrict management interface access to a trusted management VLAN or specific admin hosts rather than exposing it broadly.
- Enforce strong unique admin credentials and avoid reusing router sessions in other browser tabs.
- Disable or block unused CGI endpoints and features (SNMP, Samba, DDNS, URL filtering) that carry the vulnerable parameters.
- Monitor D-Link advisories for end-of-support status and plan hardware replacement accordingly.
Detection
- Inspect web server or proxy logs for requests to the affected CGI paths (sntpcfg.cgi, ddnsmngr.cmd, todmngr.tod, urlfilter.cmd, scprttrg.cmd, scoutflt.cmd, portmapcfg.cmd, snmpconfig.cgi, scinflt.cmd, prmngr.cmd, ippcfg.cmd, samba.cgi, wlcfg.wl) containing script tags or encoded HTML in the listed parameters.
- Alert on configuration changes to NTP, DDNS, SNMP community, Samba, or wireless SSID settings made outside expected maintenance windows.
- Review admin session activity for anomalous source IPs or concurrent sessions that could indicate session hijacking after script execution.
- Search for outbound connections from the router to unexpected hosts following configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-5223 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-5223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-5223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.