CVE-2026-7027

A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used.
References
Link Resource
https://vuldb.com/submit/797896 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359607 Third Party Advisory VDB Entry
https://vuldb.com/vuln/359607/cti Permissions Required VDB Entry
https://www.dlink.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dsl-2740r_firmware:eu_01.15:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-2740r:-:*:*:*:*:*:*:*

History

30 Apr 2026, 14:10

Type Values Removed Values Added
First Time Dlink dsl-2740r
Dlink dsl-2740r Firmware
Dlink
References () https://vuldb.com/submit/797896 - () https://vuldb.com/submit/797896 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/359607 - () https://vuldb.com/vuln/359607 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/359607/cti - () https://vuldb.com/vuln/359607/cti - Permissions Required, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product
CPE cpe:2.3:o:dlink:dsl-2740r_firmware:eu_01.15:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl-2740r:-:*:*:*:*:*:*:*

26 Apr 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-26 09:16

Updated : 2026-04-30 14:10


NVD link : CVE-2026-7027

Mitre link : CVE-2026-7027

CVE.ORG link : CVE-2026-7027


JSON object : View

Products Affected

dlink

  • dsl-2740r
  • dsl-2740r_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')