VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2016-1558CriApr 21, 2017
    risk 0.64cvss 9.8epss 0.09

    Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, and DAP-3662 1.01 and…

  • CVE-2017-6205CriFeb 23, 2017
    risk 0.64cvss 9.8epss 0.02

    D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Command Bypass attacks via unspecified vectors.

  • CVE-2016-10182CriJan 30, 2017
    risk 0.64cvss 9.8epss 0.09

    An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

  • CVE-2016-10178CriJan 30, 2017
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.

  • CVE-2016-10177CriJan 30, 2017
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.

  • CVE-2020-8863HigMar 23, 2020
    risk 0.63cvss 8.8epss 0.77

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2026-86509CriSep 8, 2026
    risk 0.62cvss 9.6epss 0.01

    A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit…

  • CVE-2026-0625CriJan 5, 2026
    risk 0.61cvss —epss 0.01

    Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can…

  • CVE-2025-13607CriDec 10, 2025
    risk 0.61cvss 9.4epss 0.01

    A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

  • CVE-2013-10050HigAug 1, 2025
    risk 0.61cvss 8.8epss 0.14

    An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing…

  • CVE-2022-46552HigFeb 2, 2023
    risk 0.61cvss 8.8epss 0.10

    D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

  • CVE-2019-17525HigApr 21, 2020
    risk 0.61cvss 8.8epss 0.06

    The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.

  • CVE-2019-20501HigMar 5, 2020
    risk 0.61cvss 7.8epss 0.90

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter.

  • CVE-2019-20499HigMar 5, 2020
    risk 0.61cvss 7.8epss 0.95

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or configServerip parameter.

  • CVE-2013-7051HigFeb 4, 2020
    risk 0.61cvss 8.8epss 0.16

    D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

  • CVE-2018-17442HigOct 8, 2018
    risk 0.61cvss 8.8epss 0.14

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.

  • CVE-2018-12710HigAug 29, 2018
    risk 0.61cvss 8.0epss 0.77

    An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being…

  • CVE-2017-17020HigMay 1, 2018
    risk 0.61cvss 8.8epss 0.15

    On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated…

  • CVE-2018-5371HigJan 12, 2018
    risk 0.61cvss 8.8epss 0.42

    diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

  • CVE-2017-7852HigApr 24, 2017
    risk 0.61cvss 8.8epss 0.04

    D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from…

  • CVE-2025-10666HigSep 18, 2025
    risk 0.60cvss 8.8epss 0.03

    A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has…

  • CVE-2024-10914HigNov 6, 2024
    risk 0.60cvss 8.1epss 0.96

    A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name…

  • CVE-2024-44334HigSep 9, 2024
    risk 0.60cvss 8.8epss 0.32

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of…

  • CVE-2024-40505CriJul 16, 2024
    risk 0.60cvss 9.3epss 0.00

    Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

  • CVE-2023-44412HigMay 3, 2024
    risk 0.60cvss 8.2epss 0.84

    D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-25331CriMar 12, 2024
    risk 0.60cvss 9.3epss 0.00

    DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.

  • CVE-2023-33782HigJun 7, 2023
    risk 0.60cvss 8.8epss 0.37

    D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.

  • CVE-2023-33781HigJun 7, 2023
    risk 0.60cvss 8.8epss 0.32

    An issue in D-Link DIR-842V2 v1.0.3 allows attackers to execute arbitrary commands via importing a crafted file.

  • CVE-2021-46441HigApr 27, 2022
    risk 0.60cvss 8.8epss 0.33

    In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

  • CVE-2013-7053HigFeb 4, 2020
    risk 0.60cvss 8.8epss 0.03

    D-Link DIR-100 4.03B07: cli.cgi CSRF

  • CVE-2014-3136HigDec 27, 2019
    risk 0.60cvss 8.8epss 0.03

    Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors.

  • CVE-2019-1010155CriJul 23, 2019
    risk 0.60cvss 9.1epss 0.09

    D-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE: Third parties dispute this issues as not being a vulnerability because although the wizard is accessible without authentication,…

  • CVE-2017-7851HigNov 15, 2017
    risk 0.60cvss 8.8epss 0.02

    D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.

  • CVE-2017-7398HigApr 4, 2017
    risk 0.60cvss 8.8epss 0.03

    D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from…

  • CVE-2017-6411HigMar 6, 2017
    risk 0.60cvss 8.8epss 0.03

    Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.

  • CVE-2026-101081CriSep 28, 2026
    risk 0.59cvss 9.1epss —

    A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt results in stack-based buffer overflow. The…

  • CVE-2026-93958CriSep 20, 2026
    risk 0.59cvss 9.1epss 0.03

    A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has…

  • CVE-2026-91003CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The…

  • CVE-2026-90703CriSep 14, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been…

  • CVE-2026-90702CriSep 14, 2026
    risk 0.59cvss 9.1epss 0.04

    A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.

  • CVE-2026-85224CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched…

  • CVE-2026-85222CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command…

  • CVE-2026-82691CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command…

  • CVE-2026-82690CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.04

    A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out…

  • CVE-2026-82688CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.04

    A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name…

  • CVE-2024-10915HigNov 6, 2024
    risk 0.59cvss 8.1epss 0.80

    A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to…

  • CVE-2024-33110CriMay 6, 2024
    risk 0.59cvss 9.1epss 0.01

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.

  • CVE-2023-32166HigMay 3, 2024
    risk 0.59cvss 8.1epss 0.74

    D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of D-Link D-View. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-29385CriMar 22, 2024
    risk 0.59cvss 9.0epss 0.02

    DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.

  • CVE-2023-44959HigOct 10, 2023
    risk 0.59cvss 8.8epss 0.21

    An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.

Page 11 of 39