Vulnerability index

Browse CVEs

96 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-17787 On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is… Dir 823g Firmware No fix yet Fix from $2,3002018-10-02 HIGH 7.2 CVE-2018-16408 D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTomographySettings request by le… Dir 846 Firmware No fix yet Fix from $1,9502018-09-03 CRITICAL 9.8 CVE-2018-6213 In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0… Dir 620 Firmware No fix yet Fix from $2,3002018-06-20 HIGH 7.2 CVE-2018-6211EPSS 6% On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command in… Dir 620 Firmware No fix yet Fix from $1,9502018-06-20 MEDIUM 6.1 CVE-2018-6212 On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected C… Dir 620 Firmware No fix yet Fix from $1,6002018-06-20 CRITICAL 9.8 CVE-2018-10968 On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable d… Dir 550a Firmware after 2.10kr Fix from $2,3002018-05-18 HIGH 8.8 CVE-2018-10967 On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be e… Dir 550a Firmware after 2.10kr Fix from $1,9502018-05-18 CRITICAL 9.8 CVE-2018-11013EPSS 7% Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthenti… Dir 816 A2 Firmware No fix yet Fix from $2,3002018-05-13 CRITICAL 9.8 CVE-2018-10996EPSS 5% The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buf… Dir 629 B Firmware No fix yet Fix from $2,3002018-05-12 HIGH 8.8 CVE-2018-10746 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tca… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10747 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10748 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tc… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10749 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10750 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/b… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10713 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tc… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-03 HIGH 7.2 CVE-2018-10431 D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen. Dir 615 Firmware No fix yet Fix from $1,9502018-04-26 HIGH 8.8 CVE-2018-8941EPSS 7% Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execu… Dsl 3782 Firmware No fix yet Fix from $1,9502018-04-03 HIGH 8.1 CVE-2018-7698 An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and… Mydlink\+ Mitigation only Fix from $1,9502018-03-05 MEDIUM 5.4 CVE-2018-6936 Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account. Dir 600m C1 Firmware No fix yet Fix from $1,6002018-02-21 HIGH 8.8 CVE-2018-5371EPSS 42% diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote… Dsl 2540u Firmware No fix yet Fix from $1,9502018-01-12 CRITICAL 9.8 CVE-2017-3191EPSS 63% D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote att… Dir 130 Firmware Mitigation only Fix from $2,3002017-12-16 CRITICAL 9.8 CVE-2017-3192EPSS 39% D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp pag… Dir 130 Firmware Mitigation only Fix from $2,3002017-12-16 HIGH 8.8 CVE-2017-7851 D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a subst… Dcs 936l 1.05.07+ Fix from $1,9502017-11-15 CRITICAL 9.8 CVE-2016-10405 Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions vi… Dir 600l Firmware after 1.16 Fix from $2,3002017-09-07 CRITICAL 9.8 CVE-2014-7857EPSS 15% D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and … Dns 322l Firmware after 2.00b07 Fix from $2,3002017-08-25 CRITICAL 9.8 CVE-2014-7858EPSS 15% The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username c… Dnr 326 Firmware after 1.40b03 Fix from $2,3002017-08-25 CRITICAL 9.8 CVE-2014-7859EPSS 21% Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before … Dns 322l Firmware after 2.00b07 Fix from $2,3002017-08-25 MEDIUM 5.3 CVE-2014-7860EPSS 10% The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which … Dns 327l Firmware after 1.03b04 Fix from $1,6002017-08-25 MEDIUM 6.1 CVE-2017-10676 On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter. Dir 600m Firmware Patch available Fix from $1,6002017-07-20 CRITICAL 9.8 CVE-2017-9542EPSS 5% D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to val… Dir 615 Firmware Mitigation only Fix from $2,3002017-06-11