VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2026-42374CriMay 4, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn61_dlwbr_dir600L" read from /etc/alpha_config/image_sign. The…

  • CVE-2026-42373CriMay 4, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn76_dlwbr_dir605L" read from /etc/alpha_config/image_sign.…

  • CVE-2026-7248CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.04

    A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made…

  • CVE-2026-4184CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow.…

  • CVE-2026-4183CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be…

  • CVE-2026-4182CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.02

    A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote…

  • CVE-2026-4181CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.02

    A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack…

  • CVE-2025-70245CriMar 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.

  • CVE-2025-29165CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

  • CVE-2025-70233CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.

  • CVE-2025-70232CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.

  • CVE-2025-70231CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin, it enters /goform/getAuthCode but fails to filter the value of the FILECODE parameter, resulting in a path traversal…

  • CVE-2025-70230CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.

  • CVE-2025-70229CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule.

  • CVE-2025-70222CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.

  • CVE-2025-70225CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component

  • CVE-2025-70221CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.

  • CVE-2025-46108CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

  • CVE-2025-70219CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.03

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.

  • CVE-2025-70226CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

  • CVE-2025-70223CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.

  • CVE-2025-70220CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.

  • CVE-2025-70218CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.

  • CVE-2026-3485CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.06

    A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.…

  • CVE-2025-70240CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.

  • CVE-2025-70239CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

  • CVE-2025-70234CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

  • CVE-2025-70241CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

  • CVE-2025-70237CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.

  • CVE-2025-70236CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

  • CVE-2025-69542CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.10

    A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper…

  • CVE-2025-15194CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to…

  • CVE-2025-60854CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

  • CVE-2025-13188CriNov 14, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument Password results in stack-based buffer overflow. Remote exploitation of…

  • CVE-2022-50596CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw…

  • CVE-2018-25120CriOct 29, 2025
    risk 0.64cvss 9.8epss 0.10

    D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters…

  • CVE-2025-60554CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEnableWizard.

  • CVE-2025-60553CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard52.

  • CVE-2025-60548CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.00

    D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings.

  • CVE-2025-55583CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.07

    D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution…

  • CVE-2025-29515CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitrary settings within the device's XML database, including the administrator’s password.

  • CVE-2025-29514CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the configuration file via providing a crafted web request.

  • CVE-2025-57105CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.03

    The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter…

  • CVE-2025-34125CriJul 16, 2025
    risk 0.64cvss —epss 0.04

    An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary…

  • CVE-2025-45931CriJun 30, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file

  • CVE-2025-45784CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis tools such as strings or…

  • CVE-2025-6121CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.03

    A vulnerability, which was classified as critical, has been found in D-Link DIR-632 FW103B08. Affected by this issue is the function get_pure_content of the component HTTP POST Request Handler. The manipulation of the argument Content-Length leads to stack-based buffer overflow.…

  • CVE-2025-5630CriJun 5, 2025
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be initiated remotely.…

  • CVE-2025-5624CriJun 5, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument port0_group/port0_remarker/ssid0_group/ssid0_remarker leads to…

  • CVE-2025-5622CriJun 5, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based…

Page 4 of 39