VYPR

Vendor CVEs

Dlink

All CVEs

1,931 total · sorted by risk
  • CVE-2024-4961MedMay 16, 2024
    risk 0.41cvss 6.3epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability is an unknown functionality of the file /user/onlineuser.php. The manipulation of the argument file_upload leads to unrestricted…

  • CVE-2024-4960MedMay 16, 2024
    risk 0.41cvss 6.3epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown function of the file interface/sysmanage/licenseauthorization.php. The manipulation of the argument file_upload leads to unrestricted…

  • CVE-2024-4699MedMay 14, 2024
    risk 0.41cvss 6.3epss 0.06

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The…

  • CVE-2023-5153MedSep 25, 2023
    risk 0.41cvss 6.3epss 0.02

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-8000 up to 20151231. This affects an unknown part of the file /Tool/querysql.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2023-5144MedSep 24, 2023
    risk 0.41cvss 6.3epss 0.06

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an unknown function of the file /sysmanage/updateos.php. The manipulation of the argument file_upload leads to unrestricted…

  • CVE-2023-5143MedSep 24, 2023
    risk 0.41cvss 6.3epss 0.04

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 up to 20151231. This issue affects some unknown processing of the file /log/webmailattach.php. The manipulation of the argument table_name leads to an unknown…

  • CVE-2024-28436MedApr 22, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitrary code via the reload parameter in the session_login.php component.

  • CVE-2024-27684MedMar 4, 2024
    risk 0.40cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability in dlapn.cgi, dldongle.cgi, dlcfg.cgi, fwup.cgi and seama.cgi in D-Link GORTAC750_A1_FW_v101b03 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

  • CVE-2021-41445MedFeb 10, 2022
    risk 0.40cvss 6.1epss 0.02

    A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.

  • CVE-2021-20133MedDec 30, 2021
    risk 0.40cvss 6.1epss 0.02

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of the day" banner to any file on the system, allowing them to read all or some of…

  • CVE-2020-26567MedOct 8, 2020
    risk 0.40cvss 5.5epss 0.17

    An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.

  • CVE-2020-25786MedSep 19, 2020
    risk 0.40cvss 6.1epss 0.01

    webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding…

  • CVE-2020-15895MedJul 22, 2020
    risk 0.40cvss 6.1epss 0.03

    An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.

  • CVE-2018-7859MedDec 30, 2019
    risk 0.40cvss 6.1epss 0.01

    A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to inject malicious scripts in the device and execute commands via browser that is configuring the unit.

  • CVE-2019-17663MedOct 16, 2019
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

  • CVE-2019-6968MedAug 2, 2019
    risk 0.40cvss 6.1epss 0.01

    The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflected.

  • CVE-2019-14338MedAug 1, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action= XSS vulnerability on the management interface.

  • CVE-2019-13562MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.

  • CVE-2019-13374MedJul 6, 2019
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

  • CVE-2018-18636MedOct 24, 2018
    risk 0.40cvss 6.1epss 0.01

    XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.

  • CVE-2018-15875MedAug 25, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.

  • CVE-2018-15874MedAug 25, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.

  • CVE-2018-6212MedJun 20, 2018
    risk 0.40cvss 6.1epss 0.02

    On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filtration for special characters in the "Search" field and…

  • CVE-2018-10108MedApr 16, 2018
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.

  • CVE-2018-10107MedApr 16, 2018
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.

  • CVE-2018-6529MedMar 6, 2018
    risk 0.40cvss 6.1epss 0.02

    XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a…

  • CVE-2018-6528MedMar 6, 2018
    risk 0.40cvss 6.1epss 0.02

    XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a…

  • CVE-2018-6527MedMar 6, 2018
    risk 0.40cvss 6.1epss 0.02

    XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read…

  • CVE-2017-16765MedNov 10, 2017
    risk 0.40cvss 6.1epss 0.01

    XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.

  • CVE-2016-10699MedOct 31, 2017
    risk 0.40cvss 6.1epss 0.01

    D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a remote unauthenticated user may craft logins and passwords with script tags in them. Because there is no sanitization in the input fields, an unaware logged-in…

  • CVE-2017-14416MedSep 13, 2017
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.

  • CVE-2017-14415MedSep 13, 2017
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.

  • CVE-2017-14414MedSep 13, 2017
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php.

  • CVE-2017-14413MedSep 13, 2017
    risk 0.40cvss 6.1epss 0.01

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wpsacts.php.

  • CVE-2017-10676MedJul 20, 2017
    risk 0.40cvss 6.1epss 0.01

    On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter.

  • CVE-2026-4377MedMay 28, 2026
    risk 0.39cvss —epss 0.00

    Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the default password if they have the device IMEI number. This issue was fixed in…

  • CVE-2021-27342MedMay 17, 2021
    risk 0.39cvss 5.9epss 0.05

    An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack

  • CVE-2013-1603MedJan 28, 2020
    risk 0.39cvss 5.3epss 0.16

    An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121…

  • CVE-2013-1600MedJan 28, 2020
    risk 0.39cvss 5.3epss 0.18

    An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and 1.05_RU, which could let a malicious user obtain sensitive…

  • CVE-2013-3096MedFeb 7, 2020
    risk 0.38cvss 5.9epss 0.01

    D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

  • CVE-2013-1601MedJan 28, 2020
    risk 0.38cvss 5.3epss 0.13

    An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a…

  • CVE-2018-15516MedJan 31, 2019
    risk 0.38cvss 5.8epss 0.02

    The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via port 8000, resulting in SSRF.

  • CVE-2018-6936MedFeb 21, 2018
    risk 0.38cvss 5.4epss 0.02

    Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.

  • CVE-2017-14420MedSep 13, 2017
    risk 0.38cvss 5.9epss 0.01

    The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and…

  • CVE-2017-14419MedSep 13, 2017
    risk 0.38cvss 5.9epss 0.01

    The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service for HTTP, even though a TCP relay service…

  • CVE-2025-25896MedFeb 18, 2025
    risk 0.37cvss 5.7epss 0.00

    A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2025-25892MedFeb 18, 2025
    risk 0.37cvss 5.7epss 0.00

    A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2025-25891MedFeb 18, 2025
    risk 0.37cvss 5.7epss 0.00

    A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

  • CVE-2024-56914MedJan 22, 2025
    risk 0.37cvss 5.7epss 0.00

    D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

  • CVE-2024-13106MedJan 2, 2025
    risk 0.37cvss 5.3epss 0.27

    A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The…

Page 34 of 39