Dir 615
by Dlink
CVEs (28)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-10431 | Hig | 0.47 | 7.2 | 0.03 | Apr 26, 2018 | D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen. | ||
| CVE-2019-19743 | Med | 0.46 | 6.5 | 0.09 | Dec 16, 2019 | On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal. | ||
| CVE-2021-40654 | Med | 0.42 | 6.5 | 0.02 | Sep 24, 2021 | An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page | ||
| CVE-2018-15875 | Med | 0.40 | 6.1 | 0.01 | Aug 25, 2018 | Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request. | ||
| CVE-2018-15874 | Med | 0.40 | 6.1 | 0.01 | Aug 25, 2018 | Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request. | ||
| CVE-2024-0717 | Med | 0.36 | 5.3 | 0.18 | Jan 19, 2024 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S,… | ||
| CVE-2019-19742 | Med | 0.36 | 4.8 | 0.20 | Dec 18, 2019 | On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. | ||
| CVE-2009-4821 | 0.00 | — | 0.01 | Apr 27, 2010 | The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified… |
- risk 0.47cvss 7.2epss 0.03
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
- risk 0.46cvss 6.5epss 0.09
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
- risk 0.42cvss 6.5epss 0.02
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
- risk 0.36cvss 5.3epss 0.18
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S,…
- risk 0.36cvss 4.8epss 0.20
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
- CVE-2009-4821Apr 27, 2010risk 0.00cvss —epss 0.01
The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified…
Page 2 of 2