VYPR

Vendor CVEs

Dlink

All CVEs

1,894 total · sorted by risk
  • CVE-2012-10021CriJul 31, 2025
    risk 0.67cvss 9.8epss 0.03

    A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter…

  • CVE-2014-125117CriJul 25, 2025
    risk 0.67cvss 9.8epss 0.05

    A stack-based buffer overflow vulnerability in the my_cgi.cgi component of certain D-Link devices, including the DSP-W215 version 1.02, can be exploited via a specially crafted HTTP POST request to the /common/info.cgi endpoint. This flaw enables an unauthenticated attacker to…

  • CVE-2024-3273HigKEVApr 4, 2024
    risk 0.67cvss 7.3epss 1.00

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The…

  • CVE-2022-46476CriJan 19, 2023
    risk 0.67cvss 9.8epss 0.41

    D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.

  • CVE-2021-26709CriApr 7, 2021
    risk 0.67cvss 9.8epss 0.40

    D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. NOTE: This vulnerability only affects products that are no longer supported…

  • CVE-2016-11021HigKEVMar 9, 2020
    risk 0.67cvss 7.2epss 0.69

    setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

  • CVE-2013-5945CriFeb 11, 2020
    risk 0.67cvss 9.8epss 0.10

    Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to…

  • CVE-2013-7055CriFeb 4, 2020
    risk 0.67cvss 9.8epss 0.07

    D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

  • CVE-2018-19986CriMay 13, 2019
    risk 0.67cvss 9.8epss 0.42

    In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the…

  • CVE-2017-3192CriDec 16, 2017
    risk 0.67cvss 9.8epss 0.39

    D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page…

  • CVE-2025-29635HigKEVMar 25, 2025
    risk 0.66cvss 7.2epss 0.90

    A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

  • CVE-2024-57045CriFeb 18, 2025
    risk 0.66cvss 9.8epss 0.32

    A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

  • CVE-2024-51151CriNov 21, 2024
    risk 0.66cvss 9.8epss 0.30

    D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

  • CVE-2023-51123CriJan 10, 2024
    risk 0.66cvss 9.8epss 0.24

    An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.

  • CVE-2023-26613CriJun 29, 2023
    risk 0.66cvss 9.8epss 0.31

    An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

  • CVE-2023-34800CriJun 15, 2023
    risk 0.66cvss 9.8epss 0.29

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

  • CVE-2023-33735CriMay 31, 2023
    risk 0.66cvss 9.8epss 0.33

    D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.

  • CVE-2023-25279CriMar 13, 2023
    risk 0.66cvss 9.8epss 0.31

    OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-37130CriAug 31, 2022
    risk 0.66cvss 9.8epss 0.26

    In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability

  • CVE-2022-37057CriAug 28, 2022
    risk 0.66cvss 9.8epss 0.25

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.

  • CVE-2022-35620CriAug 3, 2022
    risk 0.66cvss 9.8epss 0.31

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

  • CVE-2022-34974CriAug 3, 2022
    risk 0.66cvss 9.8epss 0.23

    D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.

  • CVE-2022-28573CriMay 2, 2022
    risk 0.66cvss 9.8epss 0.28

    D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter.

  • CVE-2021-46314CriFeb 17, 2022
    risk 0.66cvss 9.8epss 0.33

    A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable…

  • CVE-2021-27114CriApr 14, 2021
    risk 0.66cvss 9.8epss 0.25

    An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.

  • CVE-2019-13375CriJul 6, 2019
    risk 0.66cvss 9.8epss 0.28

    A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.

  • CVE-2013-7471CriJun 11, 2019
    risk 0.66cvss 9.8epss 0.24

    An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or…

  • CVE-2018-10823HigOct 17, 2018
    risk 0.66cvss 8.8epss 0.78

    An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the…

  • CVE-2025-7206CriJul 9, 2025
    risk 0.65cvss 9.8epss 0.16

    A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file switch_language.cgi of the component httpd. The manipulation of the argument Language leads to stack-based buffer overflow. The attack…

  • CVE-2025-5623CriJun 5, 2025
    risk 0.65cvss 9.8epss 0.13

    A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to…

  • CVE-2025-44084CriMay 20, 2025
    risk 0.65cvss 9.8epss 0.18

    D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.

  • CVE-2024-57684CriJan 16, 2025
    risk 0.65cvss 9.8epss 0.14

    An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

  • CVE-2024-44400CriSep 4, 2024
    risk 0.65cvss 9.8epss 0.14

    A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.

  • CVE-2024-42812CriAug 19, 2024
    risk 0.65cvss 9.8epss 0.16

    In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

  • CVE-2024-33344CriApr 26, 2024
    risk 0.65cvss 9.8epss 0.20

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

  • CVE-2024-22651CriJan 24, 2024
    risk 0.65cvss 9.8epss 0.20

    There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.

  • CVE-2023-7163CriDec 28, 2023
    risk 0.65cvss 10.0epss 0.02

    A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes, denial of service conditions due to the probe inventory…

  • CVE-2023-44693CriOct 17, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.

  • CVE-2023-43240CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.12

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.

  • CVE-2023-43239CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.12

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.

  • CVE-2023-43237CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.12

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.

  • CVE-2023-39750CriAug 21, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.

  • CVE-2023-37791CriJul 17, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin.

  • CVE-2022-46642CriDec 23, 2022
    risk 0.65cvss 9.9epss 0.03

    D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.

  • CVE-2022-46641CriDec 23, 2022
    risk 0.65cvss 9.9epss 0.03

    D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.

  • CVE-2022-37128CriAug 31, 2022
    risk 0.65cvss 9.8epss 0.21

    In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

  • CVE-2022-37056CriAug 28, 2022
    risk 0.65cvss 9.8epss 0.10

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

  • CVE-2022-37134CriAug 22, 2022
    risk 0.65cvss 9.8epss 0.21

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

  • CVE-2022-30521CriJun 2, 2022
    risk 0.65cvss 9.8epss 0.14

    The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of…

  • CVE-2022-28956CriMay 18, 2022
    risk 0.65cvss 9.8epss 0.23

    An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.

Page 2 of 38