VYPR

DIR878

by Dlink

CVEs (51)

  • CVE-2022-37130CriAug 31, 2022
    risk 0.66cvss 9.8epss 0.26

    In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability

  • CVE-2023-27720CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27719CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27718CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24800CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24799CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24798CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2022-48108CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-48107CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-44801CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

  • CVE-2022-44202CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

  • CVE-2022-43184CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

  • CVE-2021-44882CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44880CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-30072CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

  • CVE-2020-8864HigMar 23, 2020
    risk 0.64cvss 8.8epss 0.80

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2019-9125CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.

  • CVE-2019-9124CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.

  • CVE-2020-8863HigMar 23, 2020
    risk 0.63cvss 8.8epss 0.77

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2019-8319HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

Page 1 of 3