LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2013-5223: D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2013-5223 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.

CVE-2013-5223 is a cross-site scripting (XSS) vulnerability in the D-Link DSL-2760U gateway. It allows a remote authenticated user to inject arbitrary web script or HTML into the device’s web interface. For IT and security teams, this matters because a compromised or malicious authenticated session can turn the gateway’s management UI into a vehicle for script execution in the browsers of other administrators, potentially leading to session abuse, credential theft, or further configuration changes on a device that sits at the network edge.

Public detail is limited to the product and weakness class described above. Confirm exact fixed firmware, attack surface, and any configuration prerequisites against the vendor advisory before acting.

How it works

This issue is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). In gateway and router management interfaces, XSS typically arises when user-supplied input is reflected or stored and later rendered in HTML without proper encoding or sanitization. An attacker who already has valid credentials to the D-Link DSL-2760U web UI can supply crafted input that the device later serves as active script or markup to another user’s browser.

Abuse does not require inventing specific payloads here; the practical effect is that script runs in the security context of the management interface. That can let an attacker act with the privileges of the victim administrator’s session, read or alter settings visible in the UI, or pivot toward other internal systems if the same browser session has access elsewhere. Because the summary states the attacker must be authenticated, unauthenticated remote injection is outside the documented scope; still treat any exposed management interface as high risk.

Am I affected? How to find it in your systems

The affected product is the D-Link DSL-2760U gateway. These devices commonly appear as customer-premises DSL routers or small-office gateways, often with a web-based administration interface reachable on the LAN and sometimes (mis)exposed to the WAN.

If you cannot confirm the exact model or firmware, treat any D-Link DSL gateway with an open management UI as requiring the same review until the advisory clears it.

How to remediate

Patch first. Apply updates per vendor instructions for the D-Link DSL-2760U, as directed by CISA’s required action. Obtain firmware only from the vendor’s official support channel and follow their install and verification steps. After upgrade, re-check the firmware version reported by the device and confirm that default or weak admin credentials have been rotated.

Then harden for this class of flaw:

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

These controls do not remove the XSS flaw; they limit who can reach it and how much damage a successful injection can cause.

If your data may have been exposed

Actively exploited vulnerabilities on edge devices can lead to broader compromise, including credential theft and network reconfiguration. Ransomware use of this specific CVE is not documented in the provided facts. If you suspect the management interface was abused, rotate admin and related credentials, audit gateway configuration for unauthorized changes, and review internal systems that may have been reachable from the affected network. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora, then prioritize password resets and monitoring for those identities.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · DSL-2760U
WeaknessCWE-79
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities