Lucene search

K

Dlink Security Vulnerabilities

cve
cve

CVE-2017-7852

D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a...

8.8CVSS

8.5AI Score

0.002EPSS

2017-04-24 10:59 AM
50
3
cve
cve

CVE-2013-7005

D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive...

8.3AI Score

0.0004EPSS

2013-12-19 04:24 AM
19
cve
cve

CVE-2013-5946

The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allows remote attackers to execute...

9.7AI Score

0.014EPSS

2013-12-19 04:24 AM
28
cve
cve

CVE-2016-10125

D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS...

8.1CVSS

7.8AI Score

0.002EPSS

2017-01-09 05:59 PM
19
cve
cve

CVE-2017-17020

On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated attackers to...

8.8CVSS

8.8AI Score

0.011EPSS

2018-05-01 04:29 PM
40
cve
cve

CVE-2021-42627

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of...

9.8CVSS

9.3AI Score

0.235EPSS

2022-08-23 12:15 PM
39
3
cve
cve

CVE-2014-3936

Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header....

8.3AI Score

0.964EPSS

2014-06-02 02:55 PM
26
cve
cve

CVE-2013-4772

D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a direct request when an authorized session is...

7.1AI Score

0.006EPSS

2014-05-12 02:55 PM
21
cve
cve

CVE-2012-4046

The D-Link DCS-932L camera with firmware 1.02 allows remote attackers to discover the password via a UDP broadcast packet, as demonstrated by running the D-Link Setup Wizard and reading the _paramR["P"]...

7AI Score

0.001EPSS

2022-10-03 04:15 PM
23
cve
cve

CVE-2020-24578

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash...

6.5CVSS

7AI Score

0.001EPSS

2020-12-22 07:15 PM
27
cve
cve

CVE-2019-19223

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router by submitting a reboot.html GET request without being authenticated on the admin...

7.5CVSS

7.3AI Score

0.001EPSS

2020-03-04 07:15 PM
26
cve
cve

CVE-2020-9534

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is...

8.8CVSS

8.9AI Score

0.001EPSS

2020-03-02 12:15 AM
85
cve
cve

CVE-2020-6841

D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName...

9.8CVSS

9.8AI Score

0.023EPSS

2020-02-21 04:15 PM
90
cve
cve

CVE-2013-4856

D-Link DIR-865L has Information...

6.5CVSS

6.5AI Score

0.001EPSS

2019-10-25 04:15 PM
64
cve
cve

CVE-2018-10107

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to...

6.1CVSS

6.5AI Score

0.001EPSS

2018-04-16 09:58 AM
26
cve
cve

CVE-2015-0150

The remote administration UI in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to bypass intended access restrictions via unspecified...

9.8CVSS

9.2AI Score

0.004EPSS

2018-04-12 09:29 PM
28
cve
cve

CVE-2015-2049

Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable...

7.5AI Score

0.567EPSS

2015-02-23 05:59 PM
23
cve
cve

CVE-2014-3872

Multiple SQL injection vulnerabilities in the administration login page in D-Link DAP-1350 (Rev. A1) with firmware 1.14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2)...

8.9AI Score

0.002EPSS

2014-05-27 02:00 PM
18
cve
cve

CVE-2023-24344

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-10 03:15 PM
23
cve
cve

CVE-2018-19300

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1)....

9.8CVSS

9.7AI Score

0.015EPSS

2019-04-11 04:29 PM
33
cve
cve

CVE-2013-6026

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide...

7.1AI Score

0.028EPSS

2022-10-03 04:14 PM
32
cve
cve

CVE-2014-10027

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that (1) change the MAC filter restrict mode, (2) add a MAC address to the filter, or (3)...

7.5AI Score

0.002EPSS

2022-10-03 04:20 PM
20
cve
cve

CVE-2014-3761

Cross-site scripting (XSS) vulnerability in D-Link DAP 1150 with firmware 1.2.94 allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi in the Control/URL-filter...

6AI Score

0.002EPSS

2022-10-03 04:20 PM
21
cve
cve

CVE-2019-19222

A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaScript code into the info.html administration page by sending a crafted Forms/wireless_autonetwork_1 POST...

5.4CVSS

5.1AI Score

0.001EPSS

2020-03-04 07:15 PM
41
cve
cve

CVE-2020-9535

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is...

8.8CVSS

8.9AI Score

0.001EPSS

2020-03-02 12:15 AM
85
cve
cve

CVE-2020-6842

D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer...

7.2CVSS

7.2AI Score

0.005EPSS

2020-02-21 04:15 PM
90
cve
cve

CVE-2013-4855

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba...

8.8CVSS

8.5AI Score

0.001EPSS

2019-10-25 04:15 PM
21
cve
cve

CVE-2018-17065

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return...

9.8CVSS

9.6AI Score

0.004EPSS

2018-09-15 09:29 PM
23
cve
cve

CVE-2018-17068

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum...

9.8CVSS

9.6AI Score

0.013EPSS

2018-09-15 09:29 PM
18
cve
cve

CVE-2018-10957

CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected...

8.8CVSS

8.6AI Score

0.002EPSS

2018-05-10 02:29 AM
27
cve
cve

CVE-2018-10108

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to...

6.1CVSS

6.5AI Score

0.001EPSS

2018-04-16 09:58 AM
23
cve
cve

CVE-2018-10106

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.php?a=%0a_POST_SERVICES%3DDEVICE.ACCOUNT%0aAUTHORIZED_GROUP%3D1...

9.8CVSS

9AI Score

0.004EPSS

2018-04-16 09:58 AM
26
cve
cve

CVE-2015-0153

D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless...

7.5CVSS

7.8AI Score

0.002EPSS

2018-04-12 09:29 PM
22
cve
cve

CVE-2015-1028

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy Configuration Panel); the (2) brName parameter to...

5.5AI Score

0.041EPSS

2015-01-21 03:28 PM
18
cve
cve

CVE-2011-4821

Directory traversal vulnerability in the TFTP server in D-Link DIR-601 Wireless N150 Home Router with firmware 1.02NA allows remote attackers to read arbitrary files via unspecified...

4.5AI Score

0.003EPSS

2014-06-20 02:55 PM
26
cve
cve

CVE-2023-24352

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at...

9.8CVSS

9.7AI Score

0.002EPSS

2023-02-10 03:15 PM
17
cve
cve

CVE-2023-24343

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at...

8.8CVSS

8.9AI Score

0.001EPSS

2023-02-10 03:15 PM
20
cve
cve

CVE-2017-6411

Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any...

8.8CVSS

8.8AI Score

0.002EPSS

2017-03-06 06:59 AM
41
cve
cve

CVE-2014-10026

index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by setting the client_login cookie to...

6.8AI Score

0.003EPSS

2022-10-03 04:20 PM
25
cve
cve

CVE-2023-29665

D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in...

9.8CVSS

9.6AI Score

0.002EPSS

2023-04-17 04:15 PM
14
cve
cve

CVE-2014-10028

Cross-site scripting (XSS) vulnerability in D-Link DAP-1360 router with firmware 2.5.4 and later allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi when res_config_id is set to...

6AI Score

0.002EPSS

2022-10-03 04:20 PM
18
cve
cve

CVE-2014-3760

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP 1150 with firmware 1.2.94 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable the DMZ in the Firewall/DMZ section via a request to index.cgi or (3) add, (4)...

7.5AI Score

0.002EPSS

2022-10-03 04:20 PM
20
cve
cve

CVE-2020-24579

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and...

8.8CVSS

8.8AI Score

0.047EPSS

2020-12-22 07:15 PM
34
1
cve
cve

CVE-2020-26567

An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several...

5.5CVSS

5.5AI Score

0.137EPSS

2020-10-08 01:15 PM
50
2
cve
cve

CVE-2020-13135

D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid...

6.5CVSS

6.2AI Score

0.001EPSS

2020-05-18 05:15 PM
67
cve
cve

CVE-2019-18666

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested....

9.8CVSS

9.6AI Score

0.014EPSS

2020-05-15 06:15 PM
93
cve
cve

CVE-2019-20501

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip...

7.8CVSS

7.8AI Score

0.001EPSS

2020-03-05 03:15 PM
48
cve
cve

CVE-2013-7054

D-Link DIR-100 4.03B07: cli.cgi...

6.1CVSS

7.2AI Score

0.002EPSS

2020-02-04 02:15 PM
32
cve
cve

CVE-2013-7051

D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication...

8.8CVSS

8.7AI Score

0.029EPSS

2020-02-04 02:15 PM
37
cve
cve

CVE-2013-4857

D-Link DIR-865L has PHP File Inclusion in the router xml...

9.8CVSS

9.4AI Score

0.008EPSS

2019-10-25 04:15 PM
23
Total number of security vulnerabilities844