Vendor CVEs
Dlink
All CVEs
1,932 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36092 | Cri | 0.64 | 9.8 | 0.02 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-36091 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-36090 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-36089 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2023 | Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||
| CVE-2023-26616 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo. | ||
| CVE-2023-26612 | Cri | 0.64 | 9.8 | 0.01 | Jun 29, 2023 | D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo. | ||
| CVE-2023-32224 | Cri | 0.64 | 9.8 | 0.01 | Jun 28, 2023 | D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts | ||
| CVE-2023-32222 | Cri | 0.64 | 9.8 | 0.02 | Jun 28, 2023 | D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method. | ||
| CVE-2023-33626 | Cri | 0.64 | 9.8 | 0.02 | Jun 12, 2023 | D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary. | ||
| CVE-2023-31814 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php. | ||
| CVE-2023-29961 | Cri | 0.64 | 9.8 | 0.01 | May 16, 2023 | D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup, | ||
| CVE-2023-29856 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2023 | D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary. | ||
| CVE-2023-29665 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings. | ||
| CVE-2023-27720 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27719 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-27718 | Cri | 0.64 | 9.8 | 0.01 | Apr 9, 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24800 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24799 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24798 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-24797 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2023 | D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | ||
| CVE-2023-26822 | Cri | 0.64 | 9.8 | 0.03 | Apr 1, 2023 | D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main. | ||
| CVE-2023-24762 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2023 | OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1. | ||
| CVE-2023-24352 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS. | ||
| CVE-2023-24351 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin. | ||
| CVE-2023-24350 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail. | ||
| CVE-2023-24349 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute. | ||
| CVE-2023-24348 | Cri | 0.64 | 9.8 | 0.01 | Feb 10, 2023 | D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter. | ||
| CVE-2022-47035 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2023 | Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint. | ||
| CVE-2022-48108 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload. | ||
| CVE-2022-48107 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload. | ||
| CVE-2022-46475 | Cri | 0.64 | 9.8 | 0.10 | Jan 17, 2023 | D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function. | ||
| CVE-2022-44832 | Cri | 0.64 | 9.8 | 0.04 | Dec 14, 2022 | D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function. | ||
| CVE-2022-44930 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. | ||
| CVE-2022-44929 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles. | ||
| CVE-2022-44928 | Cri | 0.64 | 9.8 | 0.03 | Dec 2, 2022 | D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. | ||
| CVE-2022-44808 | Cri | 0.64 | 9.8 | 0.04 | Nov 22, 2022 | A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the… | ||
| CVE-2022-44807 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. | ||
| CVE-2022-44806 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. | ||
| CVE-2022-44804 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. | ||
| CVE-2022-44801 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. | ||
| CVE-2022-44202 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. | ||
| CVE-2022-44201 | Cri | 0.64 | 9.8 | 0.01 | Nov 22, 2022 | D-Link DIR823G 1.02B05 is vulnerable to Commad Injection. | ||
| CVE-2022-44204 | Cri | 0.64 | 9.8 | 0.01 | Nov 18, 2022 | D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow. | ||
| CVE-2022-36786 | Cri | 0.64 | 9.9 | 0.01 | Nov 17, 2022 | DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router. | ||
| CVE-2022-43109 | Cri | 0.64 | 9.8 | 0.04 | Nov 3, 2022 | D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet. | ||
| CVE-2020-21016 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2022 | D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php. | ||
| CVE-2022-43003 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function. | ||
| CVE-2022-43002 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54. | ||
| CVE-2022-43001 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function. | ||
| CVE-2022-43000 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2022 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4. |
- risk 0.64cvss 9.8epss 0.02
Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
- risk 0.64cvss 9.8epss 0.01
D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts
- risk 0.64cvss 9.8epss 0.02
D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
- risk 0.64cvss 9.8epss 0.03
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.
- risk 0.64cvss 9.8epss 0.03
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.
- risk 0.64cvss 9.8epss 0.01
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.
- risk 0.64cvss 9.8epss 0.01
Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.
- risk 0.64cvss 9.8epss 0.03
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
- risk 0.64cvss 9.8epss 0.03
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.
- risk 0.64cvss 9.8epss 0.10
D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.
- risk 0.64cvss 9.8epss 0.03
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
- risk 0.64cvss 9.8epss 0.01
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.
- risk 0.64cvss 9.8epss 0.03
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
- risk 0.64cvss 9.8epss 0.04
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the…
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.
- risk 0.64cvss 9.9epss 0.01
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
- risk 0.64cvss 9.8epss 0.04
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.
- risk 0.64cvss 9.8epss 0.01
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.
Page 7 of 39