Vulnerability index

Browse CVEs

1,155 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dsl2888a Firmware MEDIUM 6.5
CVE-2020-24578

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali…

No fix yet
Fix from $1,600 2020-12-22
Dir 803 Firmware MEDIUM 6.1
CVE-2020-25786

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability onl…

No fix yet
Fix from $1,600 2020-09-19
Dsl 7740c Firmware MEDIUM 6.7
CVE-2020-12774

D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.

Mitigation only
Fix from $1,600 2020-07-22
Dsl 2750u Firmware HIGH 7.8
CVE-2020-13150

D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…

Mitigation only
Fix from $1,950 2020-06-15
Dsl 2730u Firmware HIGH 7.5
CVE-2020-13960

D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows …

No fix yet
Fix from $1,950 2020-06-08
Dir 865l Firmware HIGH 8.8
CVE-2020-13786

D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13783

D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13784

D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13785

D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13787

D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 8.8
CVE-2020-13782EPSS 27%

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

No fix yet
Fix from $1,950 2020-06-03
Dsp W215 Firmware HIGH 7.5
CVE-2020-13136

D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.

Mitigation only
Fix from $1,950 2020-05-18
Dsp W215 Firmware MEDIUM 6.5
CVE-2020-13135

D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy.

Mitigation only
Fix from $1,600 2020-05-18
Dir 615 Firmware HIGH 8.8
CVE-2019-17525EPSS 6%

The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.

No fix yet
Fix from $1,950 2020-04-21
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9275

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltratio…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9277

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perfor…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9279

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The log…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.1
CVE-2020-9278

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware HIGH 8.8
CVE-2020-9276

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web ser…

No fix yet
Fix from $1,950 2020-04-20
Dir 825 Firmware HIGH 8.8
CVE-2020-10213

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10214EPSS 18%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated …

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10215EPSS 5%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10216EPSS 5%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s…

No fix yet
Fix from $1,950 2020-03-07
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19224

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the confi…

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19225

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers…

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19226

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable …

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19223

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router …

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware MEDIUM 5.4
CVE-2019-19222

A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaSc…

No fix yet
Fix from $1,600 2020-03-04
Dir 615jx10 Firmware HIGH 8.8
CVE-2020-9534

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed.

No fix yet
Fix from $1,950 2020-03-02
Dir 615jx10 Firmware HIGH 8.8
CVE-2020-9535

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malforme…

No fix yet
Fix from $1,950 2020-03-02