Filtered by vendor D-link
Subscribe
Total
279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-26258 | 2 D-link, Dlink | 2 Dir-820l, Dir-820l Firmware | 2023-03-13 | 7.5 HIGH | 9.8 CRITICAL |
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | |||||
CVE-2023-0127 | 1 D-link | 2 Dwl-2600ap, Dwl-2600ap Firmware | 2023-02-21 | N/A | 7.8 HIGH |
A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root. | |||||
CVE-2023-24351 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-21 | N/A | 9.8 CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin. | |||||
CVE-2023-24350 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-17 | N/A | 9.8 CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail. | |||||
CVE-2023-24352 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-17 | N/A | 9.8 CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS. | |||||
CVE-2023-24349 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-17 | N/A | 9.8 CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute. | |||||
CVE-2023-24348 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-17 | N/A | 9.8 CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter. | |||||
CVE-2023-24344 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-17 | N/A | 8.8 HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup. | |||||
CVE-2023-24347 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-16 | N/A | 8.8 HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus. | |||||
CVE-2023-24345 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-16 | N/A | 8.8 HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus. | |||||
CVE-2023-24346 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-16 | N/A | 8.8 HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at /goform/formEasySetupWizard3. | |||||
CVE-2023-24343 | 2 D-link, Dlink | 2 Dir-605l, Dir-605l Firmware | 2023-02-16 | N/A | 8.8 HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule. | |||||
CVE-2022-44929 | 1 D-link | 2 Dvg-g5402sp, Dvg-g5402sp Firmware | 2022-12-05 | N/A | 9.8 CRITICAL |
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles. | |||||
CVE-2022-44928 | 1 D-link | 2 Dvg-g5402sp, Dvg-g5402sp Firmware | 2022-12-05 | N/A | 9.8 CRITICAL |
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. | |||||
CVE-2022-44930 | 1 D-link | 2 Dhp-w310av, Dhp-w310av Firmware | 2022-12-05 | N/A | 9.8 CRITICAL |
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. | |||||
CVE-2021-42627 | 2 D-link, Dlink | 8 Dir-615, Dir-615 Firmware, Dir-615 J1 and 5 more | 2022-08-24 | N/A | 9.8 CRITICAL |
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page. | |||||
CVE-2022-35191 | 2 D-link, Dlink | 2 Dsl-3782, Dsl-3782 Firmware | 2022-08-24 | N/A | 6.5 MEDIUM |
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request. | |||||
CVE-2021-21816 | 1 D-link | 2 Dir-3040, Dir-3040 Firmware | 2022-07-29 | 4.3 MEDIUM | 4.3 MEDIUM |
An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | |||||
CVE-2020-29557 | 1 D-link | 6 Dir-825, Dir-825\/a, Dir-825\/ac and 3 more | 2022-07-12 | 10.0 HIGH | 9.8 CRITICAL |
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution. | |||||
CVE-2021-33259 | 1 D-link | 2 Dir-868lw, Dir-868lw Firmware | 2022-07-12 | 5.0 MEDIUM | 5.3 MEDIUM |
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history. |