VYPR

R15 Firmware

by Dlink

CVEs (2)

  • CVE-2025-60854CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

  • CVE-2023-41603MedJan 10, 2024
    risk 0.34cvss 5.3epss 0.00

    D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.