VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2023-5147MedSep 25, 2023
    risk 0.43cvss 6.3epss 0.26

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been classified as critical. This affects an unknown part of the file /sysmanage/updateos.php. The manipulation of the argument 1_file_upload leads to unrestricted upload. It is…

  • CVE-2013-7054MedFeb 4, 2020
    risk 0.43cvss 6.1epss 0.04

    D-Link DIR-100 4.03B07: cli.cgi XSS

  • CVE-2019-6013MedDec 26, 2019
    risk 0.43cvss 6.6epss 0.01

    DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).

  • CVE-2018-17443MedOct 8, 2018
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.

  • CVE-2018-17441MedOct 8, 2018
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.

  • CVE-2026-9534MedMay 26, 2026
    risk 0.42cvss 6.3epss 0.02

    A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a manipulation of the argument PIN can lead to os command injection. It is possible to launch the attack…

  • CVE-2026-9533MedMay 26, 2026
    risk 0.42cvss 6.3epss 0.02

    A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing a manipulation of the argument fwUrl/magicid results in os command injection. It is…

  • CVE-2026-9532MedMay 26, 2026
    risk 0.42cvss 6.3epss 0.02

    A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Such manipulation of the argument FileName leads to os command injection. The…

  • CVE-2026-9531MedMay 26, 2026
    risk 0.42cvss 6.3epss 0.02

    A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried…

  • CVE-2026-9515MedMay 26, 2026
    risk 0.42cvss 6.3epss 0.02

    A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument plugin_version results in os command injection. The attack may…

  • CVE-2026-9514MedMay 25, 2026
    risk 0.42cvss 6.3epss 0.02

    A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument NetDiagHost/NetDiagPingNum/NetDiagPingSize/NetDiagPingTimeOut/Net…

  • CVE-2026-4197MedMar 16, 2026
    risk 0.42cvss 6.3epss 0.24

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function…

  • CVE-2026-0732MedJan 9, 2026
    risk 0.42cvss 6.3epss 0.12

    A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be…

  • CVE-2025-14225MedDec 8, 2025
    risk 0.42cvss 6.3epss 0.09

    A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been…

  • CVE-2025-13306MedNov 18, 2025
    risk 0.42cvss 6.3epss 0.08

    A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack…

  • CVE-2025-60701MedNov 13, 2025
    risk 0.42cvss 6.5epss 0.03

    A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration parameters (`EmailFrom`, `EmailTo`, `SMTPServerAddress`,…

  • CVE-2025-60700MedNov 13, 2025
    risk 0.42cvss 6.5epss 0.03

    A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via…

  • CVE-2025-57636MedSep 23, 2025
    risk 0.42cvss 6.5epss 0.01

    OS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability via the HTTP parameter "time".

  • CVE-2025-10634MedSep 18, 2025
    risk 0.42cvss 6.3epss 0.07

    A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes…

  • CVE-2025-10628MedSep 18, 2025
    risk 0.42cvss 6.3epss 0.09

    A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing manipulation results in command injection. The attack is possible to be carried out…

  • CVE-2025-10441MedSep 15, 2025
    risk 0.42cvss 6.3epss 0.12

    A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the file version_upgrade.asp of the component jhttpd. The manipulation of the argument path results in os command injection. The attack…

  • CVE-2025-10440MedSep 15, 2025
    risk 0.42cvss 6.3epss 0.12

    A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by this vulnerability is the function sub_4621DC of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument…

  • CVE-2025-10401MedSep 14, 2025
    risk 0.42cvss 6.3epss 0.08

    A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit…

  • CVE-2025-29522MedAug 25, 2025
    risk 0.42cvss 6.5epss 0.01

    D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.

  • CVE-2025-8956MedAug 14, 2025
    risk 0.42cvss 6.3epss 0.20

    A vulnerability was found in D-Link DIR‑818L up to 1.05B01. This issue affects the function getenv of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2025-8175MedJul 26, 2025
    risk 0.42cvss 6.5epss 0.02

    A vulnerability was found in D-Link DI-8400 16.07.26A1. It has been classified as problematic. This affects an unknown part of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument share_enable leads to null pointer dereference. It is possible to…

  • CVE-2025-6898MedJun 30, 2025
    risk 0.42cvss 6.3epss 0.14

    A vulnerability, which was classified as critical, has been found in D-Link DI-7300G+ 19.12.25A1. Affected by this issue is some unknown functionality of the file in proxy_client.asp. The manipulation of the argument proxy_srv/proxy_lanport/proxy_lanip/proxy_srvport leads to os…

  • CVE-2025-5573MedJun 4, 2025
    risk 0.42cvss 6.3epss 0.14

    A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by this issue is the function setSystemWizard/setSystemControl of the file /setSystemWizard. The manipulation of the argument AdminID leads to os command injection. The attack may be…

  • CVE-2025-5571MedJun 4, 2025
    risk 0.42cvss 6.3epss 0.14

    A vulnerability was found in D-Link DCS-932L 2.18.01. It has been classified as critical. Affected is the function setSystemAdmin of the file /setSystemAdmin. The manipulation of the argument AdminID leads to os command injection. It is possible to launch the attack remotely.…

  • CVE-2025-46176MedMay 23, 2025
    risk 0.42cvss 6.5epss 0.00

    Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.

  • CVE-2025-4454MedMay 9, 2025
    risk 0.42cvss 6.3epss 0.07

    A vulnerability was found in D-Link DIR-619L 2.04B04. It has been declared as critical. This vulnerability affects the function wake_on_lan. The manipulation of the argument mac leads to command injection. The attack can be initiated remotely. The vendor was contacted early…

  • CVE-2025-4453MedMay 9, 2025
    risk 0.42cvss 6.3epss 0.07

    A vulnerability was found in D-Link DIR-619L 2.04B04. It has been classified as critical. This affects the function formSysCmd. The manipulation of the argument sysCmd leads to command injection. It is possible to initiate the attack remotely. The vendor was contacted early…

  • CVE-2025-44023MedMay 8, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account_mgr.cgi->cgi_chg_admin_pw components.

  • CVE-2025-4341MedMay 6, 2025
    risk 0.42cvss 6.3epss 0.21

    A vulnerability classified as critical was found in D-Link DIR-880L up to 104WWb01. Affected by this vulnerability is the function sub_16570 of the file /htdocs/ssdpcgi of the component Request Header Handler. The manipulation of the argument…

  • CVE-2025-29743MedApr 22, 2025
    risk 0.42cvss 6.5epss 0.01

    D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

  • CVE-2025-1877MedMar 3, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. The manipulation of the argument a1 leads to null pointer dereference. It is possible to initiate the…

  • CVE-2024-57682MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.

  • CVE-2024-57679MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

  • CVE-2024-57678MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

  • CVE-2024-57677MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.

  • CVE-2024-57676MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

  • CVE-2024-37607MedDec 17, 2024
    risk 0.42cvss 6.5epss 0.01

    A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2024-37606MedDec 17, 2024
    risk 0.42cvss 6.5epss 0.01

    A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2024-37605MedDec 17, 2024
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2024-48272MedOct 30, 2024
    risk 0.42cvss 6.5epss 0.01

    D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

  • CVE-2024-44415MedOct 11, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.

  • CVE-2024-9004MedSep 19, 2024
    risk 0.42cvss 6.3epss 0.17

    A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack…

  • CVE-2024-8213MedAug 27, 2024
    risk 0.42cvss 6.3epss 0.07

    A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to…

  • CVE-2024-8212MedAug 27, 2024
    risk 0.42cvss 6.3epss 0.07

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been rated as…

  • CVE-2024-8210MedAug 27, 2024
    risk 0.42cvss 6.3epss 0.07

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been classified…

Page 31 of 39