VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2024-11066HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.02

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.

  • CVE-2024-11065HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11064HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11063HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11062HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2023-5151MedSep 25, 2023
    risk 0.47cvss 6.3epss 0.81

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-8000 up to 20151231. Affected by this vulnerability is an unknown functionality of the file /autheditpwd.php. The manipulation of the argument hid_id leads to sql injection. The attack…

  • CVE-2022-46570HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan3Settings module.

  • CVE-2022-46569HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.02

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key parameter in the SetWLanRadioSecurity module.

  • CVE-2022-46568HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPassword parameter in the SetSysEmailSettings module.

  • CVE-2022-46566HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetQuickVPNSettings module.

  • CVE-2022-46563HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetDynamicDNSSettings module.

  • CVE-2022-46562HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK parameter in the SetQuickVPNSettings module.

  • CVE-2022-46561HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWanSettings module.

  • CVE-2022-46560HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetWan2Settings module.

  • CVE-2021-21819HigJul 16, 2021
    risk 0.47cvss 7.2epss 0.03

    A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2020-6765HigApr 10, 2020
    risk 0.47cvss 7.2epss 0.01

    D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstrated by ping -c1 127.0.0.1; cat/etc/passwd. The CLI is reachable by TELNET.

  • CVE-2020-6842HigFeb 21, 2020
    risk 0.47cvss 7.2epss 0.02

    D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.

  • CVE-2012-6614HigFeb 19, 2020
    risk 0.47cvss 7.2epss 0.03

    D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.

  • CVE-2012-6613HigJan 25, 2020
    risk 0.47cvss 7.2epss 0.02

    D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

  • CVE-2018-16408HigSep 3, 2018
    risk 0.47cvss 7.2epss 0.05

    D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by leveraging admin access.

  • CVE-2018-6211HigJun 20, 2018
    risk 0.47cvss 7.2epss 0.06

    On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.

  • CVE-2018-10431HigApr 26, 2018
    risk 0.47cvss 7.2epss 0.03

    D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.

  • CVE-2025-51281HigAug 25, 2025
    risk 0.46cvss 7.0epss 0.00

    D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability allows authenticated attackers to cause a Denial of Service (DoS) by sending crafted GET requests with overly long values for these…

  • CVE-2025-28398HigApr 1, 2025
    risk 0.46cvss 7.1epss 0.01

    D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.

  • CVE-2025-28395HigApr 1, 2025
    risk 0.46cvss 7.1epss 0.01

    D-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.

  • CVE-2023-41217HigMay 3, 2024
    risk 0.46cvss 7.1epss 0.01

    D-Link DIR-3040 prog.cgi SetQuickVPNSettings Password Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required…

  • CVE-2023-32153MedMay 3, 2024
    risk 0.46cvss 6.8epss 0.23

    D-Link DIR-2640 EmailFrom Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to exploit this…

  • CVE-2023-32150MedMay 3, 2024
    risk 0.46cvss 6.8epss 0.24

    D-Link DIR-2640 PrefixLen Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640 routers. Although authentication is required to exploit this…

  • CVE-2021-34201HigJun 16, 2021
    risk 0.46cvss 7.1epss 0.01

    D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.

  • CVE-2019-19743MedDec 16, 2019
    risk 0.46cvss 6.5epss 0.09

    On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

  • CVE-2018-18767HigDec 20, 2018
    risk 0.46cvss 7.0epss 0.01

    An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and…

  • CVE-2025-4443MedMay 9, 2025
    risk 0.45cvss 6.3epss 0.58

    A vulnerability was found in D-Link DIR-605L 2.13B01. It has been rated as critical. This issue affects the function sub_454F2C. The manipulation of the argument sysCmd leads to command injection. The attack may be initiated remotely. The vendor was contacted early about this…

  • CVE-2025-65731MedJan 8, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access…

  • CVE-2025-60674MedNov 13, 2025
    risk 0.44cvss 6.8epss 0.01

    A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets…

  • CVE-2025-29517MedAug 25, 2025
    risk 0.44cvss 6.8epss 0.02

    D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.

  • CVE-2025-8231MedJul 27, 2025
    risk 0.44cvss 6.8epss 0.01

    A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the file rgbin of the component UART Port. The manipulation leads to hard-coded credentials. It is possible to launch the attack on…

  • CVE-2024-36755MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.

  • CVE-2023-51623MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetAPClientSettings Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51622MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetTriggerPPPoEValidate Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51621MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetDeviceSettings Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51620MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetIPv6PppoeSettings Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51619MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetMyDLinkRegistration Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51618MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetWLanRadioSecurity Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51617MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetWanSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to exploit…

  • CVE-2023-51616MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetSysEmailSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51615MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetQuickVPNSettings PSK Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is required to…

  • CVE-2023-51614MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-X3260 prog.cgi SetQuickVPNSettings Password Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is…

  • CVE-2023-44416MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DAP-2622 Telnet CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2023-41228MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-3040 prog.cgi SetUsersSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit…

  • CVE-2023-41227MedMay 3, 2024
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-3040 prog.cgi SetTriggerPPPoEValidate Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to…

Page 29 of 39