VYPR

Vendor CVEs

Dlink

All CVEs

1,935 total · sorted by risk
  • CVE-2022-43001CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

  • CVE-2022-43000CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

  • CVE-2022-42998CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.

  • CVE-2022-43184CriOct 19, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

  • CVE-2022-36588CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.02

    In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.

  • CVE-2022-37125CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

  • CVE-2022-38557CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

  • CVE-2022-36756CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.03

    DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

  • CVE-2022-36755CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

  • CVE-2022-36525CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.

  • CVE-2022-36523CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

  • CVE-2022-35619CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.03

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.

  • CVE-2022-32092CriJun 27, 2022
    risk 0.64cvss 9.8epss 0.06

    D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.

  • CVE-2022-28932CriMay 23, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

  • CVE-2022-29327CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.

  • CVE-2022-29326CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

  • CVE-2022-29325CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.

  • CVE-2022-29324CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

  • CVE-2022-29323CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

  • CVE-2022-29321CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

  • CVE-2022-28915CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.07

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

  • CVE-2022-28901CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-28896CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-28895CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-28571CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.05

    D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

  • CVE-2021-43474CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.03

    An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

  • CVE-2021-43722CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.

  • CVE-2021-44127CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.03

    In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

  • CVE-2021-31326CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.

  • CVE-2021-46319CriFeb 17, 2022
    risk 0.64cvss 9.8epss 0.07

    Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users can use this vulnerability to use "\ " or backticks to bypass the shell metacharacters in the ssid0 or ssid1 parameters to execute…

  • CVE-2021-46315CriFeb 17, 2022
    risk 0.64cvss 9.8epss 0.07

    Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the…

  • CVE-2021-46457CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.

  • CVE-2021-46456CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerability allows attackers to execute arbitrary commands via the wl(0).(0)_maclist parameter.

  • CVE-2021-46455CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable parameter.

  • CVE-2021-46454CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnerability allows attackers to execute arbitrary commands via the ApCliKeyStr parameter.

  • CVE-2021-46453CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.

  • CVE-2021-46452CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography_ping_number,…

  • CVE-2021-46233CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.

  • CVE-2021-46232CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.

  • CVE-2021-46231CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.

  • CVE-2021-46230CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

  • CVE-2021-46229CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.

  • CVE-2021-46228CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

  • CVE-2021-46227CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.

  • CVE-2021-46226CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.

  • CVE-2021-45998CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44882CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44881CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44880CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-33274CriDec 1, 2021
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function FUN_80040af8 in /formWlanSetup. This vulnerability is triggered via a crafted POST request.

Page 8 of 39