Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 3040 Firmware HIGH 7.5
CVE-2021-21817

An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network …

No fix yet
Fix from $1,950 2021-07-16
Dir 3040 Firmware HIGH 7.5
CVE-2021-21818

A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network requ…

No fix yet
Fix from $1,950 2021-07-16
Dap 1330 Firmware HIGH 8.8
CVE-2021-34827

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Aut…

Mitigation only
Fix from $1,950 2021-07-15
Dap 1330 Firmware HIGH 8.8
CVE-2021-34828

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Aut…

Mitigation only
Fix from $1,950 2021-07-15
Dap 1330 Firmware HIGH 8.8
CVE-2021-34829

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Aut…

Mitigation only
Fix from $1,950 2021-07-15
Dap 1330 Firmware HIGH 8.8
CVE-2021-34830

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Aut…

Mitigation only
Fix from $1,950 2021-07-15
Dsl 2888a Firmware CRITICAL 9.8
CVE-2021-33346

There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the …

No fix yet
Fix from $2,300 2021-06-24
Dir 2640 Us Firmware HIGH 8.1
CVE-2021-34203

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in t…

Mitigation only
Fix from $1,950 2021-06-16
Dir 2640 Us Firmware HIGH 7.1
CVE-2021-34201

D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-…

No fix yet
Fix from $1,950 2021-06-16
Dir 2640 Us Firmware MEDIUM 6.8
CVE-2021-34204

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in …

No fix yet
Fix from $1,600 2021-06-16
Dir 2640 Us Firmware HIGH 7.8
CVE-2021-34202

There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be elevated to admini…

No fix yet
Fix from $1,950 2021-06-16
Dir 868l Firmware HIGH 7.5
CVE-2020-29321

The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent…

No fix yet
Fix from $1,950 2021-06-04
Dir 880l Firmware HIGH 7.5
CVE-2020-29322

The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthent…

No fix yet
Fix from $1,950 2021-06-04
Dir 885l Mfc Firmware HIGH 7.5
CVE-2020-29323

The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that al…

No fix yet
Fix from $1,950 2021-06-04
Dir 895l Mfc Firmware HIGH 7.5
CVE-2020-29324

The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an un…

No fix yet
Fix from $1,950 2021-06-04
Dir 842e Firmware MEDIUM 5.9
CVE-2021-27342

An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker t…

Fix: after 3.0.2
Fix from $1,600 2021-05-17
Dap 1880ac Firmware CRITICAL 9.8
CVE-2021-20697

Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an au…

Fix: after 1.21
Fix from $2,300 2021-04-26
Dap 1880ac Firmware HIGH 8.8
CVE-2021-20694

Improper access control vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to bypass access restric…

Fix: after 1.21
Fix from $1,950 2021-04-26
Dap 1880ac Firmware HIGH 8.8
CVE-2021-20695

Improper following of a certificate's chain of trust vulnerability in DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated atta…

Fix: after 1.21
Fix from $1,950 2021-04-26
Dap 1880ac Firmware HIGH 8.8
CVE-2021-20696

DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted r…

Fix: after 1.21
Fix from $1,950 2021-04-26
Dap 2020 Firmware HIGH 8.8
CVE-2021-27248

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access p…

Patch available
Fix from $1,950 2021-04-14
Dap 2020 Firmware HIGH 8.8
CVE-2021-27249EPSS 5%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi access p…

Patch available
Fix from $1,950 2021-04-14
Dap 2020 Firmware MEDIUM 6.5
CVE-2021-27250EPSS 67%

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 v1.01rc001 Wi-Fi …

Patch available
Fix from $1,600 2021-04-14
Dir 816 Firmware CRITICAL 9.8
CVE-2021-27113

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…

No fix yet
Fix from $2,300 2021-04-14
Dir 816 Firmware CRITICAL 9.8
CVE-2021-27114EPSS 25%

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry…

No fix yet
Fix from $2,300 2021-04-14
Dir 802 Firmware HIGH 8.8
CVE-2021-29379

An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker …

Fix: after 1.00b05
Fix from $1,950 2021-04-12
Dir 846 Firmware CRITICAL 9.8
CVE-2020-27600EPSS 14%

HNAP1/control/SetMasterWLanSettings.php in D-Link D-Link Router DIR-846 DIR-846 A1_100.26 allows remote attackers to execute arbitrary commands via s…

No fix yet
Fix from $2,300 2021-04-02
Dir 878 Firmware CRITICAL 9.8
CVE-2021-30072

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does no…

Fix: after 1.30b08
Fix from $2,300 2021-04-02
Dir 816 Firmware CRITICAL 9.8
CVE-2021-26810

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in…

No fix yet
Fix from $2,300 2021-03-30
Dir 841 Firmware HIGH 8.0
CVE-2021-28143EPSS 46%

/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).

Patch available
Fix from $1,950 2021-03-11