VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2024-13102MedJan 2, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as critical was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This vulnerability affects unknown code of the file /goform/DDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack can be initiated remotely.…

  • CVE-2024-36831MedDec 17, 2024
    risk 0.35cvss 5.3epss 0.01

    A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request without authentication.

  • CVE-2024-28730MedNov 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to obtain sensitive information via the file upload feature of the VPN configuration module.

  • CVE-2024-10916MedNov 6, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is…

  • CVE-2024-8461MedSep 5, 2024
    risk 0.35cvss 5.3epss 0.02

    A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the…

  • CVE-2023-37325MedMay 7, 2024
    risk 0.35cvss 5.4epss 0.00

    D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this…

  • CVE-2024-33113MedMay 6, 2024
    risk 0.35cvss 5.3epss 0.03

    D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

  • CVE-2024-33111MedMay 6, 2024
    risk 0.35cvss 5.4epss 0.01

    D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

  • CVE-2023-34856MedJun 9, 2023
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability in D-Link DI-7500G-CI-19.05.29A allows attackers to execute arbitrary code via uploading a crafted HTML file to the interface /auth_pic.cgi.

  • CVE-2021-46353MedMar 4, 2022
    risk 0.35cvss 5.3epss 0.02

    An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.

  • CVE-2021-46108MedFeb 18, 2022
    risk 0.35cvss 5.4epss 0.01

    D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.

  • CVE-2021-33259MedOct 31, 2021
    risk 0.35cvss 5.3epss 0.02

    Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

  • CVE-2019-19222MedMar 4, 2020
    risk 0.35cvss 5.4epss 0.02

    A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page by sending a crafted Forms/wireless_autonetwork_1 POST request.

  • CVE-2018-17989MedApr 1, 2019
    risk 0.35cvss 5.4epss 0.01

    A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when…

  • CVE-2018-16605MedSep 12, 2018
    risk 0.35cvss 5.4epss 0.01

    D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.

  • CVE-2014-7860MedAug 25, 2017
    risk 0.35cvss 5.3epss 0.10

    The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and…

  • CVE-2026-90881MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made…

  • CVE-2026-11497MedJun 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely.…

  • CVE-2026-5312MedApr 1, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this…

  • CVE-2025-29521MedAug 25, 2025
    risk 0.34cvss 5.3epss 0.01

    Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack.

  • CVE-2025-29520MedAug 25, 2025
    risk 0.34cvss 5.3epss 0.01

    Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account passwords and escalate privileges.

  • CVE-2025-4903MedMay 19, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This affects the function sub_41F4F0 of the file /H5/webgl.asp?tggl_port=0&remote_management=0&http_passwd=game&exec_service=admin-restart. The manipulation leads to unverified…

  • CVE-2024-57681MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.

  • CVE-2024-57680MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.

  • CVE-2024-0921MedJan 26, 2024
    risk 0.34cvss 4.7epss 0.38

    A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setDeviceSettings of the component Web Interface. The manipulation of the argument statuscheckpppoeuser leads…

  • CVE-2023-41603MedJan 10, 2024
    risk 0.34cvss 5.3epss 0.00

    D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.

  • CVE-2019-11017MedApr 18, 2019
    risk 0.34cvss 4.8epss 0.01

    On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.

  • CVE-2018-10110MedApr 18, 2018
    risk 0.34cvss 4.8epss 0.03

    D-Link DIR-615 T1 devices allow XSS via the Add User feature.

  • CVE-2025-4901MedMay 19, 2025
    risk 0.33cvss 4.3epss 0.77

    A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack…

  • CVE-2023-4711MedSep 1, 2023
    risk 0.33cvss 5.0epss 0.07

    A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230819. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to os command injection. The attack may be…

  • CVE-2026-1419MedJan 26, 2026
    risk 0.32cvss 4.7epss 0.17

    A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched…

  • CVE-2024-52755MedNov 21, 2024
    risk 0.32cvss 4.9epss 0.01

    D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp function.

  • CVE-2024-52757MedNov 20, 2024
    risk 0.32cvss 4.9epss 0.01

    D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.

  • CVE-2024-52754MedNov 20, 2024
    risk 0.32cvss 4.9epss 0.01

    D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function.

  • CVE-2023-5322MedOct 1, 2023
    risk 0.32cvss 4.7epss 0.17

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sysmanage/edit_manageadmin.php. The manipulation of the argument id leads to sql…

  • CVE-2026-8273MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.06

    A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely.

  • CVE-2026-8272MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.06

    A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been…

  • CVE-2026-8271MedMay 11, 2026
    risk 0.31cvss 4.7epss 0.06

    A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the file /cgi-bin/network_mgr.cgi. The manipulation leads to os command injection.…

  • CVE-2026-2227MedFeb 9, 2026
    risk 0.31cvss 4.7epss 0.06

    A vulnerability was found in D-Link DCS-931L up to 1.13.0. Impacted is the function doSystem of the file /setSystemAdmin. Performing a manipulation of the argument AdminID results in command injection. The attack may be initiated remotely. The exploit has been made public and…

  • CVE-2026-2163MedFeb 8, 2026
    risk 0.31cvss 4.7epss 0.06

    A vulnerability was identified in D-Link DIR-600 up to 2.15WWb02. This vulnerability affects unknown code of the file ssdp.cgi. Such manipulation of the argument HTTP_ST/REMOTE_ADDR/REMOTE_PORT/SERVER_ID leads to command injection. The attack may be launched remotely. The…

  • CVE-2026-2082MedFeb 7, 2026
    risk 0.31cvss 4.7epss 0.05

    A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /goform/set_mac_clone. Such manipulation of the argument mac leads to os command injection. The attack may be performed from remote. The exploit is publicly…

  • CVE-2026-2081MedFeb 7, 2026
    risk 0.31cvss 4.7epss 0.06

    A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /goform/set_password. This manipulation of the argument http_passwd causes os command injection. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-2063MedFeb 6, 2026
    risk 0.31cvss 4.7epss 0.05

    A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /goform/set_ac_server of the component Web Management Interface. The manipulation of the argument ac_server results in os command injection. The attack can be…

  • CVE-2026-2061MedFeb 6, 2026
    risk 0.31cvss 4.7epss 0.05

    A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file /goform/set_ipv6. Executing a manipulation can lead to os command injection. It is possible to launch the attack remotely. The exploit has been publicly…

  • CVE-2025-12296MedOct 27, 2025
    risk 0.31cvss 4.7epss 0.07

    A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Update Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed…

  • CVE-2025-11665MedOct 13, 2025
    risk 0.31cvss 4.7epss 0.07

    A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The attack may be initiated remotely. This vulnerability only…

  • CVE-2025-11335MedOct 6, 2025
    risk 0.31cvss 4.7epss 0.05

    A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of the component jhttpd. This manipulation of the argument iface causes command injection. The attack is possible to…

  • CVE-2025-9745MedAug 31, 2025
    risk 0.31cvss 4.7epss 0.10

    A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated…

  • CVE-2025-7553MedJul 14, 2025
    risk 0.31cvss 4.7epss 0.04

    A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This affects an unknown part of the component System Time Page. The manipulation of the argument NTP Server leads to os command injection. It is possible to initiate the attack remotely.…

  • CVE-2025-2717MedMar 25, 2025
    risk 0.31cvss 4.7epss 0.05

    A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument target_addr leads to os…

Page 36 of 39