DIR878
by Dlink
CVEs (51)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-37130 | Cri | 0.66 | 9.8 | 0.26 | Aug 31, 2022 | In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability | ||
| CVE-2023-27720 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27719 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27718 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24800 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24799 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24798 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2022-48108 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload. | ||
| CVE-2022-48107 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload. | ||
| CVE-2022-44801 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. | ||
| CVE-2022-44202 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. | ||
| CVE-2022-43184 | Cri | 0.64 | 9.8 | 0.02 | Oct 19, 2022 | D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi. | ||
| CVE-2021-44882 | Cri | 0.64 | 9.8 | 0.05 | Feb 4, 2022 | D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request. | ||
| CVE-2021-44880 | Cri | 0.64 | 9.8 | 0.04 | Feb 4, 2022 | D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request. | ||
| CVE-2021-30072 | Cri | 0.64 | 9.8 | 0.01 | Apr 2, 2021 | An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication. | ||
| CVE-2020-8864 | Hig | 0.64 | 8.8 | 0.80 | Mar 23, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | ||
| CVE-2019-9125 | Cri | 0.64 | 9.8 | 0.03 | Feb 25, 2019 | An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header. | ||
| CVE-2019-9124 | Cri | 0.64 | 9.8 | 0.02 | Feb 25, 2019 | An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password. | ||
| CVE-2020-8863 | Hig | 0.63 | 8.8 | 0.77 | Mar 23, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | ||
| CVE-2019-8319 | Hig | 0.58 | 8.8 | 0.08 | Feb 13, 2019 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted… |
- risk 0.66cvss 9.8epss 0.26
In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.03
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
- risk 0.64cvss 9.8epss 0.03
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
- risk 0.64cvss 9.8epss 0.05
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
- risk 0.64cvss 9.8epss 0.04
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.
- risk 0.64cvss 8.8epss 0.80
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
- risk 0.63cvss 8.8epss 0.77
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
- risk 0.58cvss 8.8epss 0.08
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…
Page 1 of 3