Vulnerability index

Browse CVEs

72 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dir 629 B Firmware CRITICAL 9.8
CVE-2018-10996EPSS 5%

The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buf…

No fix yet
Fix from $2,300 2018-05-12
Dsl 3782 Firmware HIGH 8.8
CVE-2018-10746

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tca…

No fix yet
Fix from $1,950 2018-05-04
Dsl 3782 Firmware HIGH 8.8
CVE-2018-10747

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/…

No fix yet
Fix from $1,950 2018-05-04
Dsl 3782 Firmware HIGH 8.8
CVE-2018-10748

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tc…

No fix yet
Fix from $1,950 2018-05-04
Dsl 3782 Firmware HIGH 8.8
CVE-2018-10749

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/…

No fix yet
Fix from $1,950 2018-05-04
Dsl 3782 Firmware HIGH 8.8
CVE-2018-10750

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/b…

No fix yet
Fix from $1,950 2018-05-04
Dsl 3782 Firmware HIGH 8.8
CVE-2018-10713

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tc…

No fix yet
Fix from $1,950 2018-05-03
Dir 615 Firmware HIGH 7.2
CVE-2018-10431

D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.

No fix yet
Fix from $1,950 2018-04-26
Dsl 3782 Firmware HIGH 8.8
CVE-2018-8941EPSS 7%

Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execu…

No fix yet
Fix from $1,950 2018-04-03
Mydlink\+ HIGH 8.1
CVE-2018-7698

An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and…

Mitigation only
Fix from $1,950 2018-03-05
Dir 600m C1 Firmware MEDIUM 5.4
CVE-2018-6936

Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.

No fix yet
Fix from $1,600 2018-02-21
Dsl 2540u Firmware HIGH 8.8
CVE-2018-5371EPSS 42%

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote…

No fix yet
Fix from $1,950 2018-01-12
Dir 130 Firmware CRITICAL 9.8
CVE-2017-3191EPSS 63%

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote att…

Mitigation only
Fix from $2,300 2017-12-16
Dir 130 Firmware CRITICAL 9.8
CVE-2017-3192EPSS 39%

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp pag…

Mitigation only
Fix from $2,300 2017-12-16
Dir 615 Firmware CRITICAL 9.8
CVE-2017-9542EPSS 5%

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to val…

Mitigation only
Fix from $2,300 2017-06-11
Dvg N5402sp Firmware CRITICAL 9.8
CVE-2015-7246EPSS 14%

D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account,…

No fix yet
Fix from $2,300 2017-04-24
Dvg N5402sp Firmware CRITICAL 9.8
CVE-2015-7247EPSS 10%

D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super an…

No fix yet
Fix from $2,300 2017-04-24
Dvg N5402sp Firmware HIGH 7.5
CVE-2015-7245EPSS 45%

Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive…

No fix yet
Fix from $1,950 2017-04-24
Dir 615 Firmware HIGH 8.8
CVE-2017-7398

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted acti…

No fix yet
Fix from $1,950 2017-04-04
Di 524 Firmware HIGH 8.0
CVE-2017-5633

Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) chan…

No fix yet
Fix from $1,950 2017-03-06
Dcs 2103 Hd Cube Network Camera Firmware MEDIUM 5.0
CVE-2014-9238

D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cg…

No fix yet
Fix from $1,600 2014-12-03
Dcs 2103 Hd Cube Network Camera Firmware MEDIUM 5.0
CVE-2014-9234

Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrar…

No fix yet
Fix from $1,600 2014-12-03
Di 604 MEDIUM 6.8
CVE-2010-2293

The Ping tools web interface in Dlink Di-604 router allows remote authenticated users to cause a denial of service via a large "ip textfield" size.

Mitigation only
Fix from $1,600 2010-06-15
Dir 400 HIGH 10.0
CVE-2009-3347

Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a…

No fix yet
Fix from $1,950 2009-09-24
Dph 540 HIGH 7.8
CVE-2007-3347

The D-Link DPH-540/DPH-541 phone accepts SIP INVITE messages that are not from the Call Server's IP address, which allows remote attackers to engage …

Mitigation only
Fix from $1,950 2007-06-22
Tftp Server HIGH 10.0
CVE-2007-1435EPSS 43%

Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which t…

Mitigation only
Fix from $1,950 2007-03-13
Dwl 2000ap\+ HIGH 7.8
CVE-2006-6538

D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or w…

No fix yet
Fix from $1,950 2006-12-14
Dwl G132 HIGH 10.0
CVE-2006-6055EPSS 6%

Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code via a 80…

Mitigation only
Fix from $1,950 2006-11-22
Dsl G624t MEDIUM 5.0
CVE-2006-5536EPSS 14%

Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary fi…

No fix yet
Fix from $1,600 2006-10-26
Dsl G624t MEDIUM 5.0
CVE-2006-5538

D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to list contents of the cgi-bin directory via unspecified vectors, probabl…

No fix yet
Fix from $1,600 2006-10-26