VYPR

Dir 878 Firmware

by Dlink

CVEs (23)

  • CVE-2023-24798CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2021-44882CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44880CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-30072CriApr 2, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

  • CVE-2019-9125CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.

  • CVE-2019-9124CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.

  • CVE-2020-8863HigMar 23, 2020
    risk 0.63cvss 8.8epss 0.77

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2019-8319HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8318HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8317HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8316HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.07

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8315HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8314HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8313HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8312HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.07

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2022-26670HigApr 7, 2022
    risk 0.57cvss 8.8epss 0.02

    D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.

  • CVE-2024-48630HigOct 17, 2024
    risk 0.52cvss 8.0epss 0.02

    D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

  • CVE-2022-1262HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.

  • CVE-2025-60674MedNov 13, 2025
    risk 0.44cvss 6.8epss 0.01

    A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets…

  • CVE-2025-60676MedNov 13, 2025
    risk 0.43cvss 6.5epss 0.03

    An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell…

Page 1 of 2