Vulnerability index

Browse CVEs

1,155 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dir 842 Firmware CRITICAL 9.8
CVE-2020-8962

A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when hand…

No fix yet
Fix from $2,300 2020-02-13
Dir865l Firmware MEDIUM 5.9
CVE-2013-3096

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

No fix yet
Fix from $1,600 2020-02-07
Dir 100 Firmware CRITICAL 9.8
CVE-2013-7055EPSS 7%

D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

No fix yet
Fix from $2,300 2020-02-04
Dir 100 Firmware MEDIUM 6.1
CVE-2013-7054

D-Link DIR-100 4.03B07: cli.cgi XSS

No fix yet
Fix from $1,600 2020-02-04
Dir 100 Firmware CRITICAL 9.8
CVE-2013-7052EPSS 25%

D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

No fix yet
Fix from $2,300 2020-02-04
Dir 100 Firmware HIGH 8.8
CVE-2013-7051EPSS 16%

D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

No fix yet
Fix from $1,950 2020-02-04
Dir 100 Firmware HIGH 8.8
CVE-2013-7053

D-Link DIR-100 4.03B07: cli.cgi CSRF

No fix yet
Fix from $1,950 2020-02-04
Dcs 3411 Firmware HIGH 7.5
CVE-2013-1602EPSS 15%

An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01,…

No fix yet
Fix from $1,950 2020-01-28
Dcs 3411 Firmware MEDIUM 5.3
CVE-2013-1603EPSS 16%

An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, D…

No fix yet
Fix from $1,600 2020-01-28
Dcs 2102 Firmware MEDIUM 5.3
CVE-2013-1600EPSS 19%

An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_…

No fix yet
Fix from $1,600 2020-01-28
Dcs 3411 Firmware MEDIUM 5.3
CVE-2013-1601EPSS 13%

An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LI…

No fix yet
Fix from $1,600 2020-01-28
Dcs 3411 Firmware CRITICAL 9.8
CVE-2013-1599EPSS 40%

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01…

No fix yet
Fix from $2,300 2020-01-28
Dsr 250n Firmware HIGH 7.2
CVE-2012-6613

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

No fix yet
Fix from $1,950 2020-01-25
Dir 601 Firmware CRITICAL 9.8
CVE-2019-16327

D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-…

No fix yet
Fix from $2,300 2019-12-26
Dir 601 Firmware HIGH 8.8
CVE-2019-16326

D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-20…

No fix yet
Fix from $1,950 2019-12-26
Dir 615 T1 Firmware MEDIUM 6.5
CVE-2019-19743EPSS 9%

On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

No fix yet
Fix from $1,600 2019-12-16
Dap 1860 Firmware HIGH 8.8
CVE-2019-19597EPSS 21%

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an …

No fix yet
Fix from $1,950 2019-12-05
Dap 1860 Firmware HIGH 8.8
CVE-2019-19598

D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value.…

No fix yet
Fix from $1,950 2019-12-05
Dir 600 B1 Firmware CRITICAL 9.8
CVE-2019-18852

Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_si…

No fix yet
Fix from $2,300 2019-11-11
Dir 865l Firmware CRITICAL 9.8
CVE-2013-4857

D-Link DIR-865L has PHP File Inclusion in the router xml file.

No fix yet
Fix from $2,300 2019-10-25
Dir 865l Firmware HIGH 8.8
CVE-2013-4855

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of th…

Mitigation only
Fix from $1,950 2019-10-25
Dir 865l Firmware MEDIUM 6.5
CVE-2013-4856

D-Link DIR-865L has Information Disclosure.

No fix yet
Fix from $1,600 2019-10-25
Dir 412 Firmware CRITICAL 9.1
CVE-2019-17512

There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file vi…

No fix yet
Fix from $2,300 2019-10-16
Dir 868l Firmware CRITICAL 9.8
CVE-2017-14948

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary cod…

No fix yet
Fix from $2,300 2019-10-14
Dir 412 Firmware HIGH 7.5
CVE-2019-17511

There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via …

No fix yet
Fix from $1,950 2019-10-14
Dir 868l B1 Firmware CRITICAL 9.8
CVE-2019-17506EPSS 56%

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the r…

No fix yet
Fix from $2,300 2019-10-11
Dir 859 A3 Firmware CRITICAL 9.8
CVE-2019-17508EPSS 16%

On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.

No fix yet
Fix from $2,300 2019-10-11
Dir 846 Firmware CRITICAL 9.8
CVE-2019-17509

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a …

No fix yet
Fix from $2,300 2019-10-11
Dir 846 Firmware CRITICAL 9.8
CVE-2019-17510

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a …

No fix yet
Fix from $2,300 2019-10-11
Dir 816 A1 Firmware HIGH 7.5
CVE-2019-17507

An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top…

No fix yet
Fix from $1,950 2019-10-11