VYPR

Vendor CVEs

Dlink

All CVEs

1,936 total · sorted by risk
  • CVE-2025-44083CriMay 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication

  • CVE-2025-29043CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234

  • CVE-2025-29042CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.02

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c

  • CVE-2025-29041CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c

  • CVE-2025-29040CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c

  • CVE-2025-2621CriMar 22, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has…

  • CVE-2025-2620CriMar 22, 2025
    risk 0.64cvss 9.8epss 0.09

    A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack…

  • CVE-2025-2619CriMar 22, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2025-2618CriMar 22, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched…

  • CVE-2025-25746CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.

  • CVE-2025-25744CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.

  • CVE-2025-25742CriFeb 12, 2025
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.

  • CVE-2024-57595CriJan 27, 2025
    risk 0.64cvss 9.8epss 0.01

    DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.

  • CVE-2025-22968CriJan 15, 2025
    risk 0.64cvss 9.8epss 0.03

    An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions

  • CVE-2024-52759CriNov 19, 2024
    risk 0.64cvss 9.8epss 0.06

    D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.

  • CVE-2024-28729CriNov 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request.

  • CVE-2024-11068CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

  • CVE-2024-48168CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.

  • CVE-2024-48150CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.

  • CVE-2024-45698CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.

  • CVE-2024-45697CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.

  • CVE-2024-45695CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.02

    The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2024-45694CriSep 16, 2024
    risk 0.64cvss 9.8epss 0.02

    The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

  • CVE-2024-44411CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.04

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

  • CVE-2024-44410CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

  • CVE-2024-44402CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

  • CVE-2024-44401CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

  • CVE-2024-45623CriSep 2, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no…

  • CVE-2024-44342CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.

  • CVE-2024-44341CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

  • CVE-2024-41622CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

  • CVE-2024-44382CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

  • CVE-2024-44381CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

  • CVE-2024-41616CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

  • CVE-2024-41611CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

  • CVE-2024-41610CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

  • CVE-2024-38438CriJul 21, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link - CWE-294: Authentication Bypass by Capture-replay

  • CVE-2024-38437CriJul 21, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

  • CVE-2024-39962CriJul 19, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.

  • CVE-2024-5296CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-44414CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. …

  • CVE-2023-44411CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The…

  • CVE-2024-27683CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.

  • CVE-2023-24331CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.02

    Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

  • CVE-2024-24321CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

  • CVE-2024-22853CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.05

    D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

  • CVE-2024-22852CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

  • CVE-2024-23625CriJan 26, 2024
    risk 0.64cvss 9.6epss 0.23

    A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

  • CVE-2024-23624CriJan 26, 2024
    risk 0.64cvss 9.6epss 0.26

    A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

  • CVE-2024-22751CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

Page 5 of 39