VYPR

Vendor CVEs

Dlink

All CVEs

1,932 total · sorted by risk
  • CVE-2023-36092CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.02

    Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-36091CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-36090CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-36089CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-26616CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.

  • CVE-2023-26612CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

  • CVE-2023-32224CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts

  • CVE-2023-32222CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.02

    D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

  • CVE-2023-33626CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.

  • CVE-2023-31814CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

  • CVE-2023-29961CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,

  • CVE-2023-29856CriMay 2, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.

  • CVE-2023-29665CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.

  • CVE-2023-27720CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27719CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27718CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24800CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24799CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24798CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-24797CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR882 DIR882A1_FW110B02 was discovered to contain a stack overflow in the sub_48AC20 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-26822CriApr 1, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at soapcgi.main.

  • CVE-2023-24762CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.03

    OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

  • CVE-2023-24352CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.

  • CVE-2023-24351CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.

  • CVE-2023-24350CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.

  • CVE-2023-24349CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

  • CVE-2023-24348CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.

  • CVE-2022-47035CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

  • CVE-2022-48108CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-48107CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-46475CriJan 17, 2023
    risk 0.64cvss 9.8epss 0.10

    D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function.

  • CVE-2022-44832CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

  • CVE-2022-44930CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

  • CVE-2022-44929CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

  • CVE-2022-44928CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

  • CVE-2022-44808CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the…

  • CVE-2022-44807CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

  • CVE-2022-44806CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

  • CVE-2022-44804CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

  • CVE-2022-44801CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

  • CVE-2022-44202CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

  • CVE-2022-44201CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

  • CVE-2022-44204CriNov 18, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

  • CVE-2022-36786CriNov 17, 2022
    risk 0.64cvss 9.9epss 0.01

    DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

  • CVE-2022-43109CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

  • CVE-2020-21016CriOct 31, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.

  • CVE-2022-43003CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.

  • CVE-2022-43002CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.

  • CVE-2022-43001CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

  • CVE-2022-43000CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

Page 7 of 39