Vulnerability index

Browse CVEs

1,155 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dir 823g Firmware CRITICAL 9.8
CVE-2021-43474

An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

No fix yet
Fix from $2,300 2022-04-07
Dir 645 Firmware CRITICAL 9.8
CVE-2021-43722

D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header on…

No fix yet
Fix from $2,300 2022-03-31
Dir 820l Firmware CRITICAL 9.8
CVE-2022-26258 KEVEPSS 80%

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

Mitigation only
Fix from $2,300 2022-03-28
Dir 816 Firmware CRITICAL 9.8
CVE-2021-31326

D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cg…

No fix yet
Fix from $2,300 2022-03-24
Dir 859 Firmware MEDIUM 5.5
CVE-2022-25106EPSS 9%

D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to ca…

No fix yet
Fix from $1,600 2022-03-04
Dap 1620 Firmware HIGH 7.5
CVE-2021-46381EPSS 58%

Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

No fix yet
Fix from $1,950 2022-03-04
Dir 850l Firmware MEDIUM 6.1
CVE-2021-46379EPSS 16%

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.

No fix yet
Fix from $1,600 2022-03-04
Dir 850l Firmware HIGH 7.5
CVE-2021-46378EPSS 32%

DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

No fix yet
Fix from $1,950 2022-03-04
Dsl 2730e Firmware MEDIUM 5.4
CVE-2021-46108

D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.

Mitigation only
Fix from $1,600 2022-02-18
Dir 846 Firmware CRITICAL 9.8
CVE-2021-46315EPSS 7%

Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enF…

No fix yet
Fix from $2,300 2022-02-17
Dir 846 Firmware CRITICAL 9.8
CVE-2021-46319EPSS 7%

Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users c…

No fix yet
Fix from $2,300 2022-02-17
Dir 820l Firmware CRITICAL 9.8
CVE-2021-45382 KEVEPSS 98%

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L rout…

Mitigation only
Fix from $2,300 2022-02-17
Dir 846 Firmware CRITICAL 9.8
CVE-2021-46314EPSS 33%

A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bi…

No fix yet
Fix from $2,300 2022-02-17
Dir 823g Firmware CRITICAL 9.8
CVE-2020-25368EPSS 9%

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exe…

Mitigation only
Fix from $2,300 2021-11-04
Dir 823g Firmware CRITICAL 9.1
CVE-2020-25366

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspe…

Mitigation only
Fix from $2,300 2021-11-04
Dir 823g Firmware CRITICAL 9.8
CVE-2020-25367EPSS 9%

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to exe…

Mitigation only
Fix from $2,300 2021-11-04
Dir 605l Firmware HIGH 7.5
CVE-2021-40655 KEVEPSS 87%

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po…

Mitigation only
Fix from $1,950 2021-09-24
Dir 615 Firmware MEDIUM 6.5
CVE-2021-40654

An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the /…

No fix yet
Fix from $1,600 2021-09-24
Dir 3040 Firmware CRITICAL 9.8
CVE-2021-21913

An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request c…

No fix yet
Fix from $2,300 2021-09-23
Dir 816 Firmware CRITICAL 9.8
CVE-2021-39510EPSS 9%

An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /gofor…

No fix yet
Fix from $2,300 2021-08-24
Dir 816 Firmware CRITICAL 9.8
CVE-2021-39509EPSS 5%

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/f…

No fix yet
Fix from $2,300 2021-08-24
Dvg 3104ms Firmware CRITICAL 9.8
CVE-2021-39613

D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' fi…

No fix yet
Fix from $2,300 2021-08-23
Dvx 2000ms Firmware CRITICAL 9.8
CVE-2021-39614

D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the pla…

No fix yet
Fix from $2,300 2021-08-23
Dsr 500n Firmware CRITICAL 9.8
CVE-2021-39615

D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in reco…

No fix yet
Fix from $2,300 2021-08-23
Dsl 2740r Firmware HIGH 7.5
CVE-2021-29294

Null Pointer Dereference vulnerability exists in D-Link DSL-2740R UK_1.01, which could let a remove malicious user cause a denial of service via the …

Mitigation only
Fix from $1,950 2021-08-10
Dsp W215 Firmware HIGH 7.5
CVE-2021-29295

Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/l…

Mitigation only
Fix from $1,950 2021-08-10
Dir 825 Firmware HIGH 7.5
CVE-2021-29296

Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial of service. The vulnerabilit…

Mitigation only
Fix from $1,950 2021-08-10
Dap 2310 Firmware HIGH 7.5
CVE-2021-28839

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 …

No fix yet
Fix from $1,950 2021-08-10
Dap 2310 Firmware HIGH 7.5
CVE-2021-28840

Null Pointer Dereference vulnerability exists in D-Link DAP-2310 2.07.RC031, DAP-2330 1.07.RC028, DAP-2360 2.07.RC043, DAP-2553 3.06.RC027, DAP-2660 …

No fix yet
Fix from $1,950 2021-08-10
Dir 615 Firmware CRITICAL 9.8
CVE-2021-37388

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver …

No fix yet
Fix from $2,300 2021-08-06