Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 818l Firmware CRITICAL 9.8
CVE-2022-35620EPSS 32%

D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

No fix yet
Fix from $2,300 2022-08-03
Dir 820l Firmware HIGH 7.5
CVE-2022-34973EPSS 15%

D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.

No fix yet
Fix from $1,950 2022-08-03
Dsl 3782 Firmware HIGH 8.8
CVE-2022-34527

D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160.

No fix yet
Fix from $1,950 2022-07-29
Dsl 3782 Firmware HIGH 8.8
CVE-2022-34528

D-Link DSL-3782 v1.03 and below was discovered to contain a stack overflow via the function getAttrValue.

No fix yet
Fix from $1,950 2022-07-29
Dir 645 Firmware CRITICAL 9.8
CVE-2022-32092EPSS 6%

D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.

Fix: after 1.03
Fix from $2,300 2022-06-27
Dir 850l Firmare HIGH 7.5
CVE-2018-18907

An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireles…

Fix: 1.21b07+
Fix from $1,950 2022-06-16
Dir 890l Firmware HIGH 8.8
CVE-2022-29778

D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtu…

Fix: after 1.22b01
Fix from $1,950 2022-06-03
Dir 890l Firmware CRITICAL 9.8
CVE-2022-30521EPSS 14%

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b0…

Fix: after 1.07b09
Fix from $2,300 2022-06-02
Dsl G2452dg Firmware CRITICAL 9.8
CVE-2022-28932

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

Mitigation only
Fix from $2,300 2022-05-23
Dir 816l Firmware CRITICAL 9.8
CVE-2022-28956EPSS 23%

An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.

No fix yet
Fix from $2,300 2022-05-18
Dir 816l Firmware HIGH 7.5
CVE-2022-28955EPSS 40%

An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.

No fix yet
Fix from $1,950 2022-05-18
Dir 825 Firmware MEDIUM 6.5
CVE-2022-29332

D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the r…

No fix yet
Fix from $1,600 2022-05-17
Dir 816 Firmware CRITICAL 9.8
CVE-2022-28915EPSS 7%

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29321

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29322EPSS 17%

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29323

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29324

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29325

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29326

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

No fix yet
Fix from $2,300 2022-05-10
Dir 816 Firmware CRITICAL 9.8
CVE-2022-29327

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.

No fix yet
Fix from $2,300 2022-05-10
Dap 1330 Firmware CRITICAL 9.8
CVE-2022-29328EPSS 14%

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.

No fix yet
Fix from $2,300 2022-05-10
Dap 1330 Firmware CRITICAL 9.8
CVE-2022-29329EPSS 14%

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings.

No fix yet
Fix from $2,300 2022-05-10
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28895

A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate priv…

No fix yet
Fix from $2,300 2022-05-10
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28896

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate pri…

No fix yet
Fix from $2,300 2022-05-10
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28901

A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileg…

No fix yet
Fix from $2,300 2022-05-10
Dir 823 Pro Firmware CRITICAL 9.8
CVE-2022-28573EPSS 28%

D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows a…

No fix yet
Fix from $2,300 2022-05-02
Dir 882 Firmware CRITICAL 9.8
CVE-2022-28571EPSS 6%

D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

No fix yet
Fix from $2,300 2022-05-02
Dir 825 Firmware CRITICAL 9.8
CVE-2021-46442EPSS 56%

In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as …

No fix yet
Fix from $2,300 2022-04-27
Dir 825 Firmware HIGH 8.8
CVE-2021-46441EPSS 33%

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary s…

No fix yet
Fix from $1,950 2022-04-27
Dir 1360 Firmware HIGH 7.8
CVE-2022-1262

A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary comm…

No fix yet
Fix from $1,950 2022-04-11