Vulnerability index

Browse CVEs

1,155 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-17505 D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can re… Dap 1320 A2 Firmware No fix yet Fix from $1,9502019-10-11 HIGH 8.2 CVE-2019-17353 An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which c… Dir 615 Firmware Mitigation only Fix from $1,9502019-10-09 CRITICAL 9.8 CVE-2019-10891EPSS 19% An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the para… Dir 806 Firmware No fix yet Fix from $2,3002019-09-06 CRITICAL 9.8 CVE-2019-10892 An issue was discovered in D-Link DIR-806 devices. There is a stack-based buffer overflow in function hnap_main at /htdocs/cgibin. The function will … Dir 806 Firmware No fix yet Fix from $2,3002019-09-06 HIGH 8.8 CVE-2019-13263 D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device… Dir 825\/ac G1 Firmware No fix yet Fix from $1,9502019-08-27 HIGH 8.8 CVE-2019-13264 D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device… Dir 825\/ac G1 Firmware No fix yet Fix from $1,9502019-08-27 HIGH 8.8 CVE-2019-13265 D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device… Dir 825\/ac G1 Firmware No fix yet Fix from $1,9502019-08-27 HIGH 8.8 CVE-2019-15526 An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v… Dir 823g Firmware No fix yet Fix from $1,9502019-08-23 HIGH 8.8 CVE-2019-15527 An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v… Dir 823g Firmware No fix yet Fix from $1,9502019-08-23 HIGH 8.8 CVE-2019-15528 An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v… Dir 823g Firmware No fix yet Fix from $1,9502019-08-23 HIGH 8.8 CVE-2019-15529EPSS 8% An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v… Dir 823g Firmware No fix yet Fix from $1,9502019-08-23 HIGH 8.8 CVE-2019-15530 An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) v… Dir 823g Firmware No fix yet Fix from $1,9502019-08-23 MEDIUM 5.5 CVE-2019-14335 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated denial of service leading to the… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-08 CRITICAL 9.8 CVE-2019-13101EPSS 67% An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lea… Dir 600m Firmware No fix yet Fix from $2,3002019-08-08 HIGH 7.5 CVE-2019-6969 The web interface of the D-Link DVA-5592 20180823 is vulnerable to an authentication bypass that allows an unauthenticated user to have access to sen… Dva 5592 Firmware No fix yet Fix from $1,9502019-08-02 MEDIUM 6.1 CVE-2019-6968 The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflected. Dva 5592 Firmware No fix yet Fix from $1,6002019-08-02 MEDIUM 6.1 CVE-2019-14338 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action= XSS vulnera… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2019-14333 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a pre-authenticated denial of service attack agains… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2019-14334 An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2019-14336 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated dump of all of the config files … 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2019-14337 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted c… 6600 Ap Firmware No fix yet Fix from $1,6002019-08-01 HIGH 7.8 CVE-2019-14332 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-… 6600 Ap Firmware No fix yet Fix from $1,9502019-08-01 CRITICAL 9.1 CVE-2019-1010155EPSS 9% D-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE:… Dsl 2750u Firmware No fix yet Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-13560 D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter. Dir 655 Firmware No fix yet Fix from $2,3002019-07-11 CRITICAL 9.8 CVE-2019-13561EPSS 8% D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_c… Dir 655 Firmware No fix yet Fix from $2,3002019-07-11 HIGH 8.8 CVE-2019-13563 D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console. Dir 655 Firmware No fix yet Fix from $1,9502019-07-11 MEDIUM 6.1 CVE-2019-13562 D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_respons… Dir 655 Firmware No fix yet Fix from $1,6002019-07-11 HIGH 8.8 CVE-2019-13481EPSS 8% An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication… Dir 818lw Firmware No fix yet Fix from $1,9502019-07-10 HIGH 8.8 CVE-2019-13482EPSS 8% An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication… Dir 818lw Firmware No fix yet Fix from $1,9502019-07-10 CRITICAL 9.8 CVE-2017-8415 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the pas… Dcs 1130 Firmware No fix yet Fix from $2,3002019-07-02