
Proof-of-concept for stored cross-site scripting (XSS) vulnerability in D-Link DSL-2730E routers via the username parameter on the maintenance password page.
██╗ ██╗███████╗███████╗
╚██╗██╔╝██╔════╝██╔════╝
╚███╔╝ ███████╗███████╗
██╔██╗ ╚════██║╚════██║
██╔╝ ██╗███████║███████║
╚═╝ ╚═╝╚══════╝╚══════╝
D-Link Router DSL-2730E - Stored Cross Site Scripting
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.
References
https://nvd.nist.gov/vuln/detail/CVE-2021-46108
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46108