VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2021-20696HigApr 26, 2021
    risk 0.57cvss 8.8epss 0.02

    DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI program.

  • CVE-2021-20695HigApr 26, 2021
    risk 0.57cvss 8.8epss 0.01

    Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to gain root privileges via unspecified vectors.

  • CVE-2021-20694HigApr 26, 2021
    risk 0.57cvss 8.8epss 0.02

    Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to bypass access restriction and to start a telnet service via unspecified vectors.

  • CVE-2021-27248HigApr 14, 2021
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access points. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of CGI…

  • CVE-2021-29379HigApr 12, 2021
    risk 0.57cvss 8.8epss 0.04

    An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet. NOTE:…

  • CVE-2020-27865HigFeb 12, 2021
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the uhttpd service,…

  • CVE-2020-27862HigFeb 12, 2021
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on…

  • CVE-2020-25759HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.

  • CVE-2020-25758HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.

  • CVE-2020-25757HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.02

    A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with…

  • CVE-2020-15633HigJul 23, 2020
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.20B10_BETA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2020-15632HigJul 23, 2020
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HNAP GetCAPTCHAsetting…

  • CVE-2020-13786HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

  • CVE-2020-9276HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web servers, is vulnerable to a remotely exploitable stack-based buffer overflow. Unauthenticated exploitation is possible by combining…

  • CVE-2020-9535HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.02

    fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malformed.

  • CVE-2020-9534HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.02

    fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed.

  • CVE-2019-16326HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE: this is an end-of-life product.

  • CVE-2019-6014HigDec 26, 2019
    risk 0.57cvss 8.8epss 0.01

    DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.

  • CVE-2019-19598HigDec 5, 2019
    risk 0.57cvss 8.8epss 0.04

    D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If…

  • CVE-2013-6811HigNov 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom…

  • CVE-2013-4855HigOct 25, 2019
    risk 0.57cvss 8.8epss 0.02

    D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

  • CVE-2019-13265HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.01

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as…

  • CVE-2019-13264HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.01

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. In order to transfer data from the host network to the guest network, the sender joins and then leaves an IGMP group. After it…

  • CVE-2019-13263HigAug 27, 2019
    risk 0.57cvss 8.8epss 0.01

    D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with…

  • CVE-2019-13563HigJul 11, 2019
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.

  • CVE-2017-8406HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on who can access the webserver. This allows an hosted flash file on any domain to make calls to the device's webserver and pull any information that is stored on…

  • CVE-2017-8407HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which…

  • CVE-2019-12787HigJun 10, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.

  • CVE-2019-12786HigJun 10, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.

  • CVE-2019-10999HigMay 6, 2019
    risk 0.57cvss 8.8epss 0.04

    The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The overflow allows a remotely authenticated attacker to execute arbitrary code by providing a long string in the WEPEncryption parameter when requesting…

  • CVE-2018-20674HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.03

    D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authenticated remote command execution.

  • CVE-2018-10957HigMay 10, 2018
    risk 0.57cvss 8.8epss 0.01

    CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.

  • CVE-2018-10750HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'staticGet <node_name attr>' function and cause memory corruption.…

  • CVE-2018-10749HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'commit <node_name>' function and cause memory corruption. Furthermore, it…

  • CVE-2018-10748HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'show <node_name>' function and cause memory corruption. Furthermore, it is…

  • CVE-2018-10747HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'unset <node_name>' function and cause memory corruption. Furthermore, it…

  • CVE-2018-10746HigMay 4, 2018
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'get <node_name attr>' function and cause memory corruption. Furthermore, it…

  • CVE-2018-10713HigMay 3, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'read <node_name>' function and cause memory corruption. Furthermore, it is…

  • CVE-2015-0151HigApr 12, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

  • CVE-2017-7404HigJul 7, 2017
    risk 0.57cvss 8.8epss 0.01

    On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim's Router without knowing the credentials (CSRF). An attacker can host a page…

  • CVE-2017-5874HigMar 22, 2017
    risk 0.57cvss 8.8epss 0.01

    CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.

  • CVE-2023-32164HigMay 3, 2024
    risk 0.56cvss 7.5epss 0.85

    D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-46381HigMar 4, 2022
    risk 0.56cvss 7.5epss 0.59

    Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

  • CVE-2021-28143HigMar 11, 2021
    risk 0.56cvss 8.0epss 0.47

    /jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).

  • CVE-2019-7390HigFeb 5, 2019
    risk 0.56cvss 8.6epss 0.02

    An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all clients in the WLAN, without authentication, via the SetWanSettings HNAP API.

  • CVE-2021-20134HigDec 30, 2021
    risk 0.55cvss 8.4epss 0.08

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file on the router's filesystem as the log file used by either Quagga service (zebra…

  • CVE-2018-10822HigOct 17, 2018
    risk 0.55cvss 7.5epss 0.39

    Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers…

  • CVE-2018-5708HigMar 30, 2018
    risk 0.55cvss 8.0epss 0.06

    An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the response (specifically, the configuration file…

  • CVE-2015-7245HigApr 24, 2017
    risk 0.55cvss 7.5epss 0.45

    Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.

  • CVE-2017-5633HigMar 6, 2017
    risk 0.55cvss 8.0epss 0.04

    Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.

Page 21 of 39