VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2023-26615HigJun 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.

  • CVE-2023-30063HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.

  • CVE-2023-30061HigMay 1, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.

  • CVE-2023-26925HigMar 31, 2023
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information.

  • CVE-2023-25281HigMar 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp.

  • CVE-2023-25283HigMar 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.

  • CVE-2022-38873HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.00

    D-Link devices DAP-2310 v2.10rc036 and earlier, DAP-2330 v1.06rc020 and earlier, DAP-2360 v2.10rc050 and earlier, DAP-2553 v3.10rc031 and earlier, DAP-2660 v1.15rc093 and earlier, DAP-2690 v3.20rc106 and earlier, DAP-2695 v1.20rc119_beta31 and earlier, DAP-3320 v1.05rc027 beta…

  • CVE-2022-46076HigDec 20, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-869 DIR869Ax_FW102B15 is vulnerable to Authentication Bypass via phpcgi.

  • CVE-2022-36785HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.02

    D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 "login.asp" A. The window.location.href = http://192.168.1.1/setupWizard.asp" http://192.168.1.1/setupWizard.asp" ;…

  • CVE-2022-42999HigOct 26, 2022
    risk 0.49cvss 7.5epss 0.03

    D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.

  • CVE-2022-31414HigSep 7, 2022
    risk 0.49cvss 7.5epss 0.02

    D-Link DIR-1960 firmware DIR-1960_A1_1.11 was discovered to contain a buffer overflow via srtcat in prog.cgi. This vulnerability allowed attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2022-36619HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.

  • CVE-2022-35192HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.

  • CVE-2022-37133HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.01

    D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.

  • CVE-2022-36526HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

  • CVE-2022-36524HigAug 15, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

  • CVE-2018-18907HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.

  • CVE-2022-27295HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27294HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27293HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.03

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27292HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

  • CVE-2022-27291HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.

  • CVE-2022-27290HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27289HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27288HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27287HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.02

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27286HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.02

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2021-41442HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.04

    An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

  • CVE-2021-41753HigSep 27, 2021
    risk 0.49cvss 7.5epss 0.02

    A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in D-Link DIR-X1560, v1.04B04, and DIR-X6060, v1.11B04 allows a remote unauthenticated attacker to disconnect a wireless client via sending specific spoofed SAE authentication frames.

  • CVE-2021-29296HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial of service. The vulnerability could be triggered by sending an HTTP request with URL /vct_wan; the sbin/httpd would invoke the strchr function and take NULL…

  • CVE-2021-29295HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/lighttpd. It could be triggered by sending an HTTP request without URL in the start line directly to the device. NOTE: The DSP-W215…

  • CVE-2021-29294HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the send_hnap_unauthorized function. It could be triggered by sending crafted POST request to /HNAP1/. NOTE: The DSL-2740R and all…

  • CVE-2021-28840HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.02

    Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_config function of…

  • CVE-2021-28839HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 1.13.RC074, DAP-2690 3.16.RC100, DAP-2695 1.17.RC063, DAP-3320 1.01.RC014 and DAP-3662 1.01.RC022 in the upload_certificate…

  • CVE-2021-28838HigAug 10, 2021
    risk 0.49cvss 7.5epss 0.02

    Null pointer dereference vulnerability in D-Link DAP-2310 2,10RC039, DAP-2330 1.10RC036 BETA, DAP-2360 2.10RC055, DAP-2553 3.10rc039 BETA, DAP-2660 1.15rc131b, DAP-2690 3.20RC115 BETA, DAP-2695 1.20RC093, DAP-3320 1.05RC027 BETA and DAP-3662 1.05rc069 in the sbin/httpd binary.…

  • CVE-2021-21818HigJul 16, 2021
    risk 0.49cvss 7.5epss 0.02

    A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-21817HigJul 16, 2021
    risk 0.49cvss 7.5epss 0.02

    An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send a sequence of requests to trigger this…

  • CVE-2020-29324HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29323HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29322HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.02

    The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29321HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-24580HigDec 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.

  • CVE-2020-15896HigJul 22, 2020
    risk 0.49cvss 7.5epss 0.02

    An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessible by any unauthorized user, e.g., logout.php and login.php. This occurs because of checking the value of NO_NEED_AUTH. If the…

  • CVE-2020-15894HigJul 22, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin…

  • CVE-2020-13960HigJun 8, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows remote attackers to provide valid DNS responses (and also offer Internet services such as HTTP) for names that otherwise would…

  • CVE-2020-13787HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.

  • CVE-2020-13785HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.

  • CVE-2020-13784HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

  • CVE-2020-13783HigJun 3, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.

  • CVE-2020-13136HigMay 18, 2020
    risk 0.49cvss 7.5epss 0.01

    D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.

Page 26 of 39