Lucene search

K

Dlink Security Vulnerabilities

cve
cve

CVE-2024-22651

There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.

9.8CVSS

9.6AI Score

0.007EPSS

2024-01-24 04:15 PM
25
cve
cve

CVE-2024-22751

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

9.8CVSS

9.6AI Score

0.001EPSS

2024-01-24 09:15 PM
140
cve
cve

CVE-2024-22852

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

9.8CVSS

9.3AI Score

0.001EPSS

2024-02-06 02:15 AM
17
cve
cve

CVE-2024-22853

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

9.8CVSS

9.3AI Score

0.002EPSS

2024-02-06 02:15 AM
132
cve
cve

CVE-2024-22916

In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

9.8CVSS

9.3AI Score

0.001EPSS

2024-01-16 10:15 PM
19
cve
cve

CVE-2024-23624

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

9.8CVSS

9.8AI Score

0.002EPSS

2024-01-26 12:15 AM
23
cve
cve

CVE-2024-23625

A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.

9.8CVSS

9.8AI Score

0.002EPSS

2024-01-26 12:15 AM
24
cve
cve

CVE-2024-24321

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

9.8CVSS

9.6AI Score

0.001EPSS

2024-02-08 06:15 PM
19
cve
cve

CVE-2024-3272

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The ma...

9.8CVSS

9.5AI Score

0.059EPSS

2024-04-04 01:15 AM
84
In Wild
cve
cve

CVE-2024-3273

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the arg...

9.8CVSS

9.7AI Score

0.929EPSS

2024-04-04 01:15 AM
120
In Wild
cve
cve

CVE-2024-38437

D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

9.8CVSS

9.6AI Score

0.001EPSS

2024-07-21 08:15 AM
30
cve
cve

CVE-2024-38438

D-Link - CWE-294: Authentication Bypass by Capture-replay

9.8CVSS

9.6AI Score

0.001EPSS

2024-07-21 08:15 AM
43
cve
cve

CVE-2024-39202

D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings.

8.8CVSS

7.5AI Score

0.001EPSS

2024-07-08 04:15 PM
28
cve
cve

CVE-2024-41616

D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

9.8CVSS

7.2AI Score

0.001EPSS

2024-08-06 04:15 PM
13
cve
cve

CVE-2024-41622

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

9.8CVSS

7.4AI Score

0.001EPSS

2024-08-27 04:15 PM
28
cve
cve

CVE-2024-44340

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

8.8CVSS

7.4AI Score

0.001EPSS

2024-08-27 04:15 PM
27
cve
cve

CVE-2024-44341

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

9.8CVSS

7.3AI Score

0.001EPSS

2024-08-27 04:15 PM
29
cve
cve

CVE-2024-44342

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.

9.8CVSS

7.3AI Score

0.001EPSS

2024-08-27 04:15 PM
30
cve
cve

CVE-2024-44375

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

7.5CVSS

7.4AI Score

0.0005EPSS

2024-09-09 02:15 PM
30
cve
cve

CVE-2024-44381

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

9.8CVSS

7.4AI Score

0.002EPSS

2024-08-23 04:15 PM
29
cve
cve

CVE-2024-44382

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

9.8CVSS

7.4AI Score

0.002EPSS

2024-08-23 04:15 PM
27
cve
cve

CVE-2024-44400

D-Link DI-8400 16.07.26A1 is vulnerable to Command Injection via upgrade_filter_asp.

9.8CVSS

7.4AI Score

0.001EPSS

2024-09-04 01:15 PM
25
cve
cve

CVE-2024-44401

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

9.8CVSS

7.3AI Score

0.001EPSS

2024-09-06 04:15 PM
23
cve
cve

CVE-2024-44402

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

9.8CVSS

7.4AI Score

0.001EPSS

2024-09-06 04:15 PM
23
cve
cve

CVE-2024-44408

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.

7.5CVSS

6.8AI Score

0.001EPSS

2024-09-06 04:15 PM
23
cve
cve

CVE-2024-44410

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

9.8CVSS

7.5AI Score

0.001EPSS

2024-09-09 09:15 PM
22
cve
cve

CVE-2024-45694

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

9.8CVSS

9.8AI Score

0.001EPSS

2024-09-16 07:15 AM
15
cve
cve

CVE-2024-45695

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

9.8CVSS

9.8AI Score

0.001EPSS

2024-09-16 07:15 AM
7
cve
cve

CVE-2024-45696

Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the sa...

8.8CVSS

8.5AI Score

0.001EPSS

2024-09-16 07:15 AM
9
cve
cve

CVE-2024-45697

Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.

9.8CVSS

9.7AI Score

0.001EPSS

2024-09-16 07:15 AM
12
cve
cve

CVE-2024-45698

Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.

9.8CVSS

8.8AI Score

0.001EPSS

2024-09-16 07:15 AM
9
cve
cve

CVE-2024-5293

D-Link DIR-2640 HTTP Referer Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2640-US routers. Authentication is not required to exploit this vulnerability. The spe...

8.8CVSS

7.8AI Score

0.001EPSS

2024-05-23 10:15 PM
51
cve
cve

CVE-2024-5298

D-Link D-View queryDeviceCustomMonitorResult Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although authentication is required to exploit this vulnerability, the existing...

8.8CVSS

8.1AI Score

0.001EPSS

2024-05-23 10:15 PM
46
cve
cve

CVE-2024-6525

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The attack may be launc...

8.8CVSS

3.9AI Score

0.002EPSS

2024-07-05 01:15 PM
28
cve
cve

CVE-2024-7436

A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The manipulation of the argument cmd leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to ...

8.8CVSS

6.9AI Score

0.001EPSS

2024-08-03 02:15 PM
10
cve
cve

CVE-2024-7715

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240812. It has been ...

6.3CVSS

7AI Score

0.0004EPSS

2024-08-13 07:15 AM
30
cve
cve

CVE-2024-7828

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to...

9.8CVSS

8.9AI Score

0.005EPSS

2024-08-15 01:15 PM
29
cve
cve

CVE-2024-7829

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and ...

9.8CVSS

8.9AI Score

0.005EPSS

2024-08-15 01:15 PM
32
cve
cve

CVE-2024-7830

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1...

9.8CVSS

8.9AI Score

0.005EPSS

2024-08-15 01:15 PM
29
cve
cve

CVE-2024-7831

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and clas...

9.8CVSS

8.9AI Score

0.005EPSS

2024-08-15 01:15 PM
28
cve
cve

CVE-2024-7832

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classifie...

8.8CVSS

8.8AI Score

0.002EPSS

2024-08-15 02:15 PM
33
cve
cve

CVE-2024-7833

A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgrade_filter.asp. The manipulation of the argument path leads to command injection. It is possible to initiate the attack remotely. The exploit has been ...

9.8CVSS

6.9AI Score

0.002EPSS

2024-08-15 02:15 PM
32
cve
cve

CVE-2024-7849

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1...

8.8CVSS

8.9AI Score

0.0004EPSS

2024-08-16 02:15 AM
33
cve
cve

CVE-2024-7922

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this ...

9.8CVSS

7.4AI Score

0.004EPSS

2024-08-19 03:15 PM
31
cve
cve

CVE-2024-8127

A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability af...

9.8CVSS

7AI Score

0.021EPSS

2024-08-24 10:15 AM
27
cve
cve

CVE-2024-8128

A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This...

9.8CVSS

7AI Score

0.021EPSS

2024-08-24 12:15 PM
33
cve
cve

CVE-2024-8129

A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected ...

9.8CVSS

7AI Score

0.021EPSS

2024-08-24 04:15 PM
27
cve
cve

CVE-2024-8130

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by ...

9.8CVSS

7AI Score

0.021EPSS

2024-08-24 05:15 PM
33
cve
cve

CVE-2024-8131

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this ...

9.8CVSS

7AI Score

0.021EPSS

2024-08-24 06:15 PM
36
cve
cve

CVE-2024-8132

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been classified as critical. This aff...

9.8CVSS

7AI Score

0.021EPSS

2024-08-24 06:15 PM
40
Total number of security vulnerabilities910