VYPR

DI-500WF

by Dlink

CVEs (3)

  • CVE-2025-7194HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerability is the function sprintf of the file ip_position.asp of the component jhttpd. The manipulation of the argument ip leads to stack-based buffer overflow. The…

  • CVE-2025-5492MedJun 3, 2025
    risk 0.41cvss 6.3epss 0.03

    A vulnerability has been found in D-Link DI-500WF-WT up to 20250511 and classified as critical. Affected by this vulnerability is the function sub_456DE8 of the file /msp_info.htm?flag=cmd of the component /usr/sbin/jhttpd. The manipulation of the argument cmd leads to command…

  • CVE-2025-9745MedAug 31, 2025
    risk 0.31cvss 4.7epss 0.10

    A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated…