VYPR

Dir 806 Firmware

by Dlink

CVEs (6)

  • CVE-2019-10891CriSep 6, 2019
    risk 0.65cvss 9.8epss 0.19

    An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the parameter that can be controlled by user, and finally allows remote attackers to execute arbitrary shell commands with a special HTTP…

  • CVE-2023-43130CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.

  • CVE-2023-43129CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.

  • CVE-2023-43128CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.

  • CVE-2019-10892CriSep 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in D-Link DIR-806 devices. There is a stack-based buffer overflow in function hnap_main at /htdocs/cgibin. The function will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users. And it…

  • CVE-2025-4340MedMay 6, 2025
    risk 0.41cvss 6.3epss 0.05

    A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit…