Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dir 823x Firmware HIGH 7.2
CVE-2025-29635 KEVEPSS 90%

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices …

Mitigation only
Fix from $1,950 2025-03-25
Dns 320l Firmware CRITICAL 9.8
CVE-2024-3272 KEVEPSS 98%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-…

Mitigation only
Fix from $2,300 2024-04-04
Dns 320l Firmware CRITICAL 9.8
CVE-2024-3273 KEVEPSS 100%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to…

Mitigation only
Fix from $2,300 2024-04-04
Dir 859 Firmware CRITICAL 9.8
CVE-2024-0769 KEVEPSS 83%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some un…

Mitigation only
Fix from $2,300 2024-01-21
Dir 820l Firmware CRITICAL 9.8
CVE-2023-25280 KEVEPSS 98%

OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_a…

Mitigation only
Fix from $2,300 2023-03-16
Dnr 322l Firmware HIGH 8.8
CVE-2022-40799 KEVEPSS 32%

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

Fix: after 2.60b15
Fix from $1,950 2022-11-29
Dsl 2750b Firmware CRITICAL 9.8
CVE-2016-20017 KEVEPSS 65%

D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016…

Fix: 1.05+
Fix from $2,300 2022-10-19
Go Rt Ac750 Firmware CRITICAL 9.8
CVE-2022-37055 KEVEPSS 56%

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

Patch available
Fix from $2,300 2022-08-28
Dir 820l Firmware CRITICAL 9.8
CVE-2022-26258 KEVEPSS 80%

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

Mitigation only
Fix from $2,300 2022-03-28
Dir 820l Firmware CRITICAL 9.8
CVE-2021-45382 KEVEPSS 98%

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L rout…

Mitigation only
Fix from $2,300 2022-02-17
Dir 605l Firmware HIGH 7.5
CVE-2021-40655 KEVEPSS 87%

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a po…

Mitigation only
Fix from $1,950 2021-09-24
Dns 320 Firmware CRITICAL 9.8
CVE-2020-25506 KEVEPSS 100%

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec…

Mitigation only
Fix from $2,300 2021-02-02
Dir 825 R1 Firmware CRITICAL 9.8
CVE-2020-29557 KEVEPSS 54%

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achi…

Fix: after 3.0.1
Fix from $2,300 2021-01-29
Dcs 4703e Firmware HIGH 8.8
CVE-2020-25079 KEVEPSS 53%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comma…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
Dcs 4603 Firmware HIGH 7.5
CVE-2020-25078 KEVEPSS 98%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint al…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
Dir 610 Firmware HIGH 8.8
CVE-2020-9377 KEVEPSS 21%

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n…

Patch available
Fix from $1,950 2020-07-09
Dcs 930l Firmware HIGH 7.2
CVE-2016-11021 KEVEPSS 69%

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

Fix: 2.12+
Fix from $1,950 2020-03-09
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20500 KEVEPSS 97%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web…

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Dir 859 Firmware CRITICAL 9.8
CVE-2019-17621 KEVEPSS 90%

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute syste…

Fix: after 3.12b04
Fix from $2,300 2019-12-30
Dir 655 Firmware CRITICAL 9.8
CVE-2019-16920 KEVEPSS 100%

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker…

Fix: after 3.02b05
Fix from $2,300 2019-09-27
Dns 320 Firmware CRITICAL 9.8
CVE-2019-16057 KEVEPSS 87%

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

Fix: after 2.05.b10
Fix from $2,300 2019-09-16
Dir 860l Firmware CRITICAL 9.8
CVE-2018-6530 KEVEPSS 97%

OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions…

Fix: after 1.12b04
Fix from $2,300 2018-03-06
Dir 626l Firmware CRITICAL 9.8
CVE-2015-1187 KEVEPSS 83%

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Mitigation only
Fix from $2,300 2017-09-21
Dir 905l Firmware CRITICAL 9.8
CVE-2014-8361 KEVEPSS 100%

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in th…

Fix: 1.15b01+
Fix from $2,300 2015-05-01
Dir 645 Firmware HIGH 8.8
CVE-2015-2051 KEVEPSS 97%

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDev…

Fix: 1.05b01+
Fix from $1,950 2015-02-23
Dir 600 Firmware HIGH 8.0
CVE-2014-100005 KEVEPSS 42%

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to …

Fix: after 2.16ww
Fix from $1,950 2015-01-13
Dsl 2760u Firmware MEDIUM 5.4
CVE-2013-5223 KEVEPSS 34%

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web sc…

Fix: 1.12+
Fix from $1,600 2013-11-19
Dir 300 Firmware MEDIUM 5.7
CVE-2011-4723 KEV

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vector…

Mitigation only
Fix from $1,600 2011-12-20