Vendor CVEs
Dlink
All CVEs
1,936 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-44083 | Cri | 0.64 | 9.8 | 0.01 | May 21, 2025 | An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication | ||
| CVE-2025-29043 | Cri | 0.64 | 9.8 | 0.02 | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234 | ||
| CVE-2025-29042 | Cri | 0.64 | 9.8 | 0.02 | Apr 17, 2025 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c | ||
| CVE-2025-29041 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2025 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c | ||
| CVE-2025-29040 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2025 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c | ||
| CVE-2025-2621 | Cri | 0.64 | 9.8 | 0.02 | Mar 22, 2025 | A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has… | ||
| CVE-2025-2620 | Cri | 0.64 | 9.8 | 0.09 | Mar 22, 2025 | A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack… | ||
| CVE-2025-2619 | Cri | 0.64 | 9.8 | 0.02 | Mar 22, 2025 | A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack… | ||
| CVE-2025-2618 | Cri | 0.64 | 9.8 | 0.02 | Mar 22, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched… | ||
| CVE-2025-25746 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module. | ||
| CVE-2025-25744 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module. | ||
| CVE-2025-25742 | Cri | 0.64 | 9.8 | 0.01 | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module. | ||
| CVE-2024-57595 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2025 | DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request. | ||
| CVE-2025-22968 | Cri | 0.64 | 9.8 | 0.03 | Jan 15, 2025 | An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions | ||
| CVE-2024-52759 | Cri | 0.64 | 9.8 | 0.06 | Nov 19, 2024 | D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. | ||
| CVE-2024-28729 | Cri | 0.64 | 9.8 | 0.01 | Nov 12, 2024 | An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request. | ||
| CVE-2024-11068 | Cri | 0.64 | 9.8 | 0.01 | Nov 11, 2024 | The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account. | ||
| CVE-2024-48168 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2024 | A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code. | ||
| CVE-2024-48150 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2024 | D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function. | ||
| CVE-2024-45698 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2024 | Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device. | ||
| CVE-2024-45697 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2024 | Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials. | ||
| CVE-2024-45695 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2024 | The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. | ||
| CVE-2024-45694 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2024 | The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. | ||
| CVE-2024-44411 | Cri | 0.64 | 9.8 | 0.04 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. | ||
| CVE-2024-44410 | Cri | 0.64 | 9.8 | 0.03 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. | ||
| CVE-2024-44402 | Cri | 0.64 | 9.8 | 0.03 | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. | ||
| CVE-2024-44401 | Cri | 0.64 | 9.8 | 0.03 | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file | ||
| CVE-2024-45623 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2024 | D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no… | ||
| CVE-2024-44342 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2024 | D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request. | ||
| CVE-2024-44341 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2024 | D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request. | ||
| CVE-2024-41622 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2024 | D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface. | ||
| CVE-2024-44382 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2024 | D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function. | ||
| CVE-2024-44381 | Cri | 0.64 | 9.8 | 0.01 | Aug 23, 2024 | D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function. | ||
| CVE-2024-41616 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service. | ||
| CVE-2024-41611 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | ||
| CVE-2024-41610 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | ||
| CVE-2024-38438 | Cri | 0.64 | 9.8 | 0.01 | Jul 21, 2024 | D-Link - CWE-294: Authentication Bypass by Capture-replay | ||
| CVE-2024-38437 | Cri | 0.64 | 9.8 | 0.01 | Jul 21, 2024 | D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel | ||
| CVE-2024-39962 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2024 | D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request. | ||
| CVE-2024-5296 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2024 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw… | ||
| CVE-2023-44414 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2024 | D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. … | ||
| CVE-2023-44411 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2024 | D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The… | ||
| CVE-2024-27683 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2024 | D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify. | ||
| CVE-2023-24331 | Cri | 0.64 | 9.8 | 0.02 | Feb 21, 2024 | Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter. | ||
| CVE-2024-24321 | Cri | 0.64 | 9.8 | 0.02 | Feb 8, 2024 | An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function. | ||
| CVE-2024-22853 | Cri | 0.64 | 9.8 | 0.05 | Feb 6, 2024 | D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session. | ||
| CVE-2024-22852 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2024 | D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload. | ||
| CVE-2024-23625 | Cri | 0.64 | 9.6 | 0.23 | Jan 26, 2024 | A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root. | ||
| CVE-2024-23624 | Cri | 0.64 | 9.6 | 0.26 | Jan 26, 2024 | A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root. | ||
| CVE-2024-22751 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2024 | D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function. |
- risk 0.64cvss 9.8epss 0.01
An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication
- risk 0.64cvss 9.8epss 0.02
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
- risk 0.64cvss 9.8epss 0.02
An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c
- risk 0.64cvss 9.8epss 0.01
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c
- risk 0.64cvss 9.8epss 0.01
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
- risk 0.64cvss 9.8epss 0.02
A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_cookie of the file /storage. The manipulation of the argument uid leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has…
- risk 0.64cvss 9.8epss 0.09
A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffer overflow. The attack…
- risk 0.64cvss 9.8epss 0.02
A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack…
- risk 0.64cvss 9.8epss 0.02
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched…
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.
- risk 0.64cvss 9.8epss 0.01
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.
- risk 0.64cvss 9.8epss 0.03
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions
- risk 0.64cvss 9.8epss 0.06
D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function.
- risk 0.64cvss 9.8epss 0.01
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request.
- risk 0.64cvss 9.8epss 0.01
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.
- risk 0.64cvss 9.8epss 0.01
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
- risk 0.64cvss 9.8epss 0.01
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.
- risk 0.64cvss 9.8epss 0.01
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.
- risk 0.64cvss 9.8epss 0.02
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.02
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.04
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
- risk 0.64cvss 9.8epss 0.01
D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no…
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.
- risk 0.64cvss 9.8epss 0.01
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
- risk 0.64cvss 9.8epss 0.01
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
- risk 0.64cvss 9.8epss 0.01
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
- risk 0.64cvss 9.8epss 0.01
D-Link - CWE-294: Authentication Bypass by Capture-replay
- risk 0.64cvss 9.8epss 0.01
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.01
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw…
- risk 0.64cvss 9.8epss 0.02
D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. …
- risk 0.64cvss 9.8epss 0.02
D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The…
- risk 0.64cvss 9.8epss 0.01
D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.
- risk 0.64cvss 9.8epss 0.02
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.
- risk 0.64cvss 9.8epss 0.02
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
- risk 0.64cvss 9.8epss 0.05
D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.
- risk 0.64cvss 9.8epss 0.01
D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.
- risk 0.64cvss 9.6epss 0.23
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
- risk 0.64cvss 9.6epss 0.26
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.
Page 5 of 39