CVE-2026-7027

A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used.
References
Link Resource
https://vuldb.com/submit/797896 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359607 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359607/cti Permissions Required VDB Entry
https://www.dlink.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dsl-2740r_firmware:eu_01.15:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-2740r:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-26 09:16

Updated : 2026-06-17 11:01


NVD link : CVE-2026-7027

Mitre link : CVE-2026-7027

CVE.ORG link : CVE-2026-7027


JSON object : View

Products Affected

dlink

  • dsl-2740r_firmware
  • dsl-2740r
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')