Medium severity5.4NVD Advisory· Published Mar 4, 2020· Updated Jun 17, 2026
CVE-2019-19222
CVE-2019-19222
Description
A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page by sending a crafted Forms/wireless_autonetwork_1 POST request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:dlink:dsl-2680_firmware:1.03:*:*:*:*:*:*:*
- D-Link/DSL-2680description
Patches
Vulnerability mechanics
References
3- github.com/0x8b30cc/DSL-2680-Multiple-Vulnerabilities/blob/master/CVE-2019-19222.mdnvdExploitThird Party Advisory
- www.dlink.com/en/security-bulletinnvdVendor Advisory
- www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfnvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.