VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2020-25366CriNov 4, 2021
    risk 0.59cvss 9.1epss 0.02

    An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

  • CVE-2020-13782HigJun 3, 2020
    risk 0.59cvss 8.8epss 0.27

    D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

  • CVE-2020-9278CriApr 20, 2020
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.

  • CVE-2020-10214HigMar 7, 2020
    risk 0.59cvss 8.8epss 0.18

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code via a POST to ntp_sync.cgi with a sufficiently long parameter ntp_server.

  • CVE-2019-19597HigDec 5, 2019
    risk 0.59cvss 8.8epss 0.21

    D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

  • CVE-2019-17512CriOct 16, 2019
    risk 0.59cvss 9.1epss 0.02

    There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file via act=clear&logtype=sysact to log_clear.php, which could be used to erase attack traces.

  • CVE-2019-9122HigFeb 25, 2019
    risk 0.59cvss 8.8epss 0.24

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.

  • CVE-2018-15517HigJan 31, 2019
    risk 0.59cvss 8.6epss 0.44

    The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/…

  • CVE-2025-8184HigJul 26, 2025
    risk 0.58cvss 8.8epss 0.11

    A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow.…

  • CVE-2025-8159HigJul 25, 2025
    risk 0.58cvss 8.8epss 0.17

    A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLanguageChange of the file /goform/formLanguageChange of the component HTTP POST Request Handler. The manipulation of the argument curTime leads to stack-based…

  • CVE-2025-7945HigJul 22, 2025
    risk 0.58cvss 8.8epss 0.06

    A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhcpplus of the file /goform/formSetWanDhcpplus. The manipulation of the argument curTime leads to buffer overflow. The attack can be…

  • CVE-2025-5572HigJun 4, 2025
    risk 0.58cvss 8.8epss 0.06

    A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability is the function setSystemEmail of the file /setSystemEmail. The manipulation of the argument EmailSMTPPortNumber leads to stack-based buffer overflow. The…

  • CVE-2025-3785HigApr 18, 2025
    risk 0.58cvss 8.8epss 0.13

    A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer…

  • CVE-2025-3538HigApr 13, 2025
    risk 0.58cvss 8.8epss 0.13

    A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been rated as critical. This issue affects the function auth_asp of the file /auth.asp of the component jhttpd. The manipulation of the argument callback leads to stack-based buffer overflow. The attack needs to be…

  • CVE-2024-44335HigSep 9, 2024
    risk 0.58cvss 8.8epss 0.12

    D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

  • CVE-2024-44333HigSep 9, 2024
    risk 0.58cvss 8.8epss 0.12

    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully…

  • CVE-2024-7828HigAug 15, 2024
    risk 0.58cvss 8.8epss 0.16

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05…

  • CVE-2024-6045HigJun 17, 2024
    risk 0.58cvss 8.8epss 0.06

    Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained…

  • CVE-2023-51629HigMay 3, 2024
    risk 0.58cvss 8.8epss 0.04

    D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-33343HigApr 26, 2024
    risk 0.58cvss 8.8epss 0.08

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

  • CVE-2022-37129HigAug 31, 2022
    risk 0.58cvss 8.8epss 0.08

    D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

  • CVE-2022-34527HigJul 29, 2022
    risk 0.58cvss 8.8epss 0.04

    D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160.

  • CVE-2021-20132HigDec 30, 2021
    risk 0.58cvss 8.8epss 0.04

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the…

  • CVE-2021-27249HigApr 14, 2021
    risk 0.58cvss 8.8epss 0.05

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of CGI…

  • CVE-2021-28144HigMar 11, 2021
    risk 0.58cvss 8.8epss 0.06

    prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context because SetVirtualServerSettings calls CheckArpTables, which calls popen unsafely.

  • CVE-2020-27864HigFeb 12, 2021
    risk 0.58cvss 8.8epss 0.10

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service,…

  • CVE-2020-24579HigDec 22, 2020
    risk 0.58cvss 8.8epss 0.10

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.

  • CVE-2020-26582HigOct 6, 2020
    risk 0.58cvss 8.8epss 0.05

    D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value for ping (aka res_config_action=3&res_config_id=18).

  • CVE-2020-10216HigMar 7, 2020
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

  • CVE-2020-10215HigMar 7, 2020
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

  • CVE-2020-10213HigMar 7, 2020
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.

  • CVE-2020-8862HigFeb 22, 2020
    risk 0.58cvss 8.8epss 0.13

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The…

  • CVE-2020-8861HigFeb 22, 2020
    risk 0.58cvss 8.8epss 0.07

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login…

  • CVE-2019-15530HigAug 23, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.

  • CVE-2019-15529HigAug 23, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.

  • CVE-2019-15528HigAug 23, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.

  • CVE-2019-15527HigAug 23, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.

  • CVE-2019-15526HigAug 23, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.

  • CVE-2019-13482HigJul 10, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings.

  • CVE-2019-13481HigJul 10, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.

  • CVE-2017-8417HigJul 2, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device requires that a user logging into the device provide a username and password. However, the device allows D-Link apps on the mobile devices and desktop to communicate with the device without any…

  • CVE-2017-8416HigJul 2, 2019
    risk 0.58cvss 8.8epss 0.12

    An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles custom D-Link UDP based protocol that allows D-Link mobile…

  • CVE-2017-8413HigJul 2, 2019
    risk 0.58cvss 8.8epss 0.10

    An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which is called "dldps2121" and listens for broadcast packets sent on 255.255.255.255. This daemon handles custom D-Link UDP based protocol that allows D-Link mobile…

  • CVE-2017-8412HigJul 2, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom binary called mp4ts under the /var/www/video folder. It seems that this binary dumps the HTTP VERB in the system logs. As a part of doing that it retrieves the HTTP VERB sent by the user and…

  • CVE-2017-8411HigJul 2, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. It seems that the POST parameters passed in this request (to test if email credentials and hostname sent to…

  • CVE-2019-13128HigJul 1, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.

  • CVE-2018-17990HigApr 1, 2019
    risk 0.58cvss 8.8epss 0.04

    An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT parameter.

  • CVE-2019-8319HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.08

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8318HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

  • CVE-2019-8317HigFeb 13, 2019
    risk 0.58cvss 8.8epss 0.06

    An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted…

Page 12 of 39