VYPR
Vendor

Draw Ctf

Products
2
CVEs
31
Across products
31
Status
Private

Products

2

Recent CVEs

31
View all 31 CVEs →
  • CVE-2026-7854CriMay 5, 2026
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack…

  • CVE-2026-7853CriMay 5, 2026
    risk 0.64cvss 9.8epss 0.02

    A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2026-76862HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers can inject crafted arguments into…

  • CVE-2026-76861HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute…

  • CVE-2026-76860HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stack buffer and corrupt program memory.

  • CVE-2026-76852HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthorized firmware…

  • CVE-2026-7855HigMay 5, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of the argument Name results in buffer overflow. The attack can be initiated…

  • CVE-2026-76856HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick authenticated administrators into modifying WAN or LAN…

  • CVE-2026-76853HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restricted restore archive handling.

  • CVE-2026-76869HigSep 15, 2026
    risk 0.47cvss 7.2epss 0.01

    Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted input to the affected endpoint to corrupt stack memory.

  • CVE-2026-76866HigSep 15, 2026
    risk 0.47cvss 7.2epss 0.01

    Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. Attackers can exploit the unsanitized parameters to inject additional…

  • CVE-2026-7857HigMay 5, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed…

  • CVE-2026-7856HigMay 5, 2026
    risk 0.47cvss 7.2epss 0.01

    A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing a manipulation of the argument Name can lead to buffer overflow. The attack can be launched remotely. The exploit has…

  • CVE-2026-7851HigMay 5, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and…

  • CVE-2026-76870HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated firmware image via put_file_cgi.c to trigger out-of-bounds reads across main.c,…

  • CVE-2026-92256MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK and RSA key material.

  • CVE-2026-76871MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and L2TP VPN credentials.

  • CVE-2026-76859MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to disclose router credentials.

  • CVE-2026-76857MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach this CGI handler can obtain plaintext DDNS…

  • CVE-2026-76855MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit components to obtain other users' session…