← back
CVE-2026-7026

D-Link DGS-3420 System Information Settings cross site scripting

CVSS 6.8 MEDIUMEPSS 0.6%CWE-79CWE-94
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.8EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DGS-3420

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →