Lucene search

K

D-Link Security Vulnerabilities

cve
cve

CVE-2022-43647

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044. The issue...

8.8CVSS

8.8AI Score

0.001EPSS

2023-03-29 07:15 PM
16
cve
cve

CVE-2022-40717

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the anweb service, which listens on TCP ports 80 and 443 by default. The issue...

8.8CVSS

8.9AI Score

0.001EPSS

2023-01-26 06:59 PM
25
cve
cve

CVE-2022-40720

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Dreambox plugin for the xupnpd service, which listens on.....

8.8CVSS

8.9AI Score

0.001EPSS

2023-01-26 06:59 PM
25
cve
cve

CVE-2022-40719

This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd_generic.lua plugin for the xupnpd service, which...

8.8CVSS

8.9AI Score

0.001EPSS

2023-01-26 06:59 PM
25
cve
cve

CVE-2022-40718

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected D-Link DIR-2150 4.0.1 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the anweb service, which listens on TCP ports 80 and 443 by default. The issue...

8.8CVSS

8.9AI Score

0.001EPSS

2023-01-26 06:59 PM
29
cve
cve

CVE-2022-41140

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The...

8.8CVSS

8.9AI Score

0.001EPSS

2023-01-26 06:59 PM
30
cve
cve

CVE-2009-3347

Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However,...

8AI Score

0.027EPSS

2022-10-03 04:23 PM
23
cve
cve

CVE-2002-2137

GlobalSunTech Wireless Access Points (1) WISECOM GL2422AP-0T, and possibly OEM products such as (2) D-Link DWL-900AP+ B1 2.1 and 2.2, (3) ALLOY GL-2422AP-S, (4) EUSSO GL2422-AP, and (5) LINKSYS WAP11-V2.2, allow remote attackers to obtain sensitive information like WEP keys, the administrator...

6.7AI Score

0.003EPSS

2022-10-03 04:23 PM
17
cve
cve

CVE-2002-1865

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 through 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote attackers to cause a denial of service (crash) via....

7.2AI Score

0.07EPSS

2022-10-03 04:23 PM
21
cve
cve

CVE-2014-9234

Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file...

6.9AI Score

0.016EPSS

2022-10-03 04:20 PM
21
cve
cve

CVE-2014-9518

Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router DIR-655 (rev Bx) with firmware before 2.12b01 allows remote attackers to inject arbitrary web script or HTML via the html_response_page...

6AI Score

0.002EPSS

2022-10-03 04:20 PM
20
cve
cve

CVE-2022-26670

D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt...

8.8CVSS

9.3AI Score

0.001EPSS

2022-04-07 07:15 PM
58
cve
cve

CVE-2021-42783

Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows an unauthenticated attacker to execute administrative...

9.8CVSS

9.6AI Score

0.002EPSS

2021-11-23 10:15 PM
27
cve
cve

CVE-2021-42784

OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform command injection via a crafted HTTP...

9.8CVSS

9.7AI Score

0.004EPSS

2021-11-23 10:15 PM
25
cve
cve

CVE-2021-34829

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the HNAP_AUTH HTTP header. The issue...

8.8CVSS

8.8AI Score

0.003EPSS

2021-07-15 06:15 PM
32
2
cve
cve

CVE-2021-34830

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the Cookie HTTP header. The issue results.....

8.8CVSS

8.8AI Score

0.004EPSS

2021-07-15 06:15 PM
26
2
cve
cve

CVE-2021-34827

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the SOAPAction HTTP header. The issue...

8.8CVSS

8.8AI Score

0.004EPSS

2021-07-15 06:15 PM
30
3
cve
cve

CVE-2021-34828

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the SOAPAction HTTP header. The issue...

8.8CVSS

8.8AI Score

0.001EPSS

2021-07-15 06:15 PM
31
3
cve
cve

CVE-2021-20694

Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to bypass access restriction and to start a telnet service via unspecified...

8.8CVSS

8.1AI Score

0.002EPSS

2021-04-26 01:15 AM
20
4
cve
cve

CVE-2021-20696

DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI...

8.8CVSS

8.7AI Score

0.006EPSS

2021-04-26 01:15 AM
22
4
cve
cve

CVE-2021-20695

Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to gain root privileges via unspecified...

8.8CVSS

8.3AI Score

0.003EPSS

2021-04-26 01:15 AM
18
4
cve
cve

CVE-2021-20697

Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via unspecified...

9.8CVSS

9.2AI Score

0.005EPSS

2021-04-26 01:15 AM
21
4
cve
cve

CVE-2020-27862

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on TCP port 8008 by...

8.8CVSS

8.9AI Score

0.003EPSS

2021-02-12 12:15 AM
41
3
cve
cve

CVE-2020-27863

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on TCP port...

6.5CVSS

6.2AI Score

0.002EPSS

2021-02-12 12:15 AM
33
2
cve
cve

CVE-2020-27865

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the uhttpd service, which listens on...

8.8CVSS

9AI Score

0.001EPSS

2021-02-12 12:15 AM
40
2
cve
cve

CVE-2020-27864

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP.....

8.8CVSS

8.8AI Score

0.003EPSS

2021-02-12 12:15 AM
42
2
cve
cve

CVE-2020-15631

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi extenders. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw...

8CVSS

8.1AI Score

0.001EPSS

2020-07-23 09:15 PM
22
cve
cve

CVE-2020-15632

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HNAP GetCAPTCHAsetting requests. The issue...

8.8CVSS

9AI Score

0.003EPSS

2020-07-23 09:15 PM
46
cve
cve

CVE-2020-12774

D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary...

8.2CVSS

6.4AI Score

0.0004EPSS

2020-07-22 08:15 AM
17
cve
cve

CVE-2020-8864

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login...

8.8CVSS

9.1AI Score

0.863EPSS

2020-03-23 09:15 PM
27
cve
cve

CVE-2020-8863

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login...

8.8CVSS

9AI Score

0.002EPSS

2020-03-23 09:15 PM
32
cve
cve

CVE-2020-9544

An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their...

7.5CVSS

7.7AI Score

0.001EPSS

2020-03-05 03:15 PM
31
cve
cve

CVE-2020-8862

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from...

8.8CVSS

9.1AI Score

0.013EPSS

2020-02-22 12:15 AM
112
cve
cve

CVE-2020-8861

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The...

8.8CVSS

9.1AI Score

0.003EPSS

2020-02-22 12:15 AM
116
cve
cve

CVE-2019-17146

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the...

9.8CVSS

9.7AI Score

0.082EPSS

2020-01-07 11:15 PM
68
cve
cve

CVE-2019-6013

DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface...

6.6CVSS

7.4AI Score

0.0004EPSS

2019-12-26 04:15 PM
27
cve
cve

CVE-2019-6014

DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User...

8.8CVSS

9AI Score

0.001EPSS

2019-12-26 04:15 PM
23
cve
cve

CVE-2013-6811

Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port...

8.8CVSS

9AI Score

0.001EPSS

2019-11-22 06:15 PM
52
cve
cve

CVE-2016-6563

Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822,...

9.8CVSS

9.4AI Score

0.967EPSS

2018-07-13 08:29 PM
109
cve
cve

CVE-2018-10996

The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a session.cgi?ACTION=logout request involving a long REMOTE_ADDR environment...

9.8CVSS

9.5AI Score

0.009EPSS

2018-05-12 04:29 AM
19
cve
cve

CVE-2018-7698

An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L) unencrypted from the app to the camera, allowing attackers to obtain these...

8.1CVSS

8.2AI Score

0.002EPSS

2018-03-05 07:29 PM
36
cve
cve

CVE-2014-9238

D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash)...

6.9AI Score

0.007EPSS

2014-12-03 09:59 PM
26
cve
cve

CVE-2013-7320

Cross-site request forgery (CSRF) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to hijack the authentication of administrators for requests that modify configuration settings via unspecified...

7.4AI Score

0.002EPSS

2014-02-06 04:10 PM
22
cve
cve

CVE-2013-7321

Cross-site scripting (XSS) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.9AI Score

0.002EPSS

2014-02-06 04:10 PM
24
cve
cve

CVE-2010-2293

The Ping tools web interface in Dlink Di-604 router allows remote authenticated users to cause a denial of service via a large "ip textfield"...

6.4AI Score

0.002EPSS

2010-06-15 02:04 PM
18
cve
cve

CVE-2010-2292

Cross-site scripting (XSS) vulnerability in the Ping tools web interface in Dlink Di-604 router allows remote attackers to inject arbitrary web script or HTML via the IP...

5.9AI Score

0.002EPSS

2010-06-15 02:04 PM
25
cve
cve

CVE-2010-0936

Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname...

6AI Score

0.006EPSS

2010-03-08 03:30 PM
22
cve
cve

CVE-2008-4771

Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products,...

8.2AI Score

0.266EPSS

2008-10-28 07:20 PM
23
cve
cve

CVE-2008-4133

The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction...

6.8AI Score

0.025EPSS

2008-09-19 05:15 PM
22
cve
cve

CVE-2008-1253

Cross-site scripting (XSS) vulnerability in cgi-bin/webcm on the D-Link DSL-G604T router allows remote attackers to inject arbitrary web script or HTML via the var:category parameter, as demonstrated by a request for advanced/portforw.htm on the fwan...

5.7AI Score

0.004EPSS

2008-03-10 05:44 PM
20
Total number of security vulnerabilities422