Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 3060 Firmware HIGH 8.8
CVE-2021-28144EPSS 6%

prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in an admin or root context bec…

Fix: after 1.11b04
Fix from $1,950 2021-03-11
Dva 2800 Firmware HIGH 8.8
CVE-2020-27862

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Au…

Mitigation only
Fix from $1,950 2021-02-12
Dap 1860 Firmware HIGH 8.8
CVE-2020-27864EPSS 10%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 …

Fix: after 1.04b03
Fix from $1,950 2021-02-12
Dap 1860 Firmware HIGH 8.8
CVE-2020-27865

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 …

Fix: after 1.04b03
Fix from $1,950 2021-02-12
Dva 2800 Firmware MEDIUM 6.5
CVE-2020-27863

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DVA-2800 and DSL-2888A rou…

Mitigation only
Fix from $1,600 2021-02-12
Dsr 250 Firmware CRITICAL 9.8
CVE-2020-18568EPSS 15%

The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.

No fix yet
Fix from $2,300 2021-02-02
Dns 320 Firmware CRITICAL 9.8
CVE-2020-25506 KEVEPSS 100%

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code exec…

Mitigation only
Fix from $2,300 2021-02-02
Dir 825 R1 Firmware CRITICAL 9.8
CVE-2020-29557 KEVEPSS 54%

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achi…

Fix: after 3.0.1
Fix from $2,300 2021-01-29
Dcs 5220 Firmware HIGH 8.0
CVE-2021-3182

D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

No fix yet
Fix from $1,950 2021-01-19
Dsl 2888a Firmware HIGH 7.5
CVE-2020-24577EPSS 19%

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive informa…

No fix yet
Fix from $1,950 2021-01-08
Dap 1650 Firmware CRITICAL 9.8
CVE-2019-12768

An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful bro…

Fix: 1.04b02_j65h+
Fix from $2,300 2020-12-30
Dsl2888a Firmware HIGH 8.8
CVE-2020-24579EPSS 10%

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authenticati…

No fix yet
Fix from $1,950 2020-12-22
Dsl2888a Firmware HIGH 8.0
CVE-2020-24581EPSS 14%

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not r…

No fix yet
Fix from $1,950 2020-12-22
Dsl2888a Firmware HIGH 7.5
CVE-2020-24580

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attack…

No fix yet
Fix from $1,950 2020-12-22
Dsl2888a Firmware MEDIUM 6.5
CVE-2020-24578

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali…

No fix yet
Fix from $1,600 2020-12-22
Dsr 150 Firmware HIGH 8.8
CVE-2020-25757

A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command API…

Fix: after 3.17
Fix from $1,950 2020-12-15
Dsr 150 Firmware HIGH 8.8
CVE-2020-25758

An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated a…

Fix: after 3.17
Fix from $1,950 2020-12-15
Dsr 150 Firmware HIGH 8.8
CVE-2020-25759

An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticat…

Fix: after 3.17
Fix from $1,950 2020-12-15
Dsr 250n Firmware MEDIUM 5.5
CVE-2020-26567EPSS 17%

An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any a…

Fix: 3.17b+
Fix from $1,600 2020-10-08
Dap 1360u Firmware HIGH 8.8
CVE-2020-26582

D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the IP JSON value fo…

Fix: 3.0.1+
Fix from $1,950 2020-10-06
Dir 803 Firmware MEDIUM 6.1
CVE-2020-25786

webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability onl…

No fix yet
Fix from $1,600 2020-09-19
Covr 2600r Firmware CRITICAL 9.8
CVE-2018-20432

D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to g…

Fix: after 1.01b05
Fix from $2,300 2020-09-14
Dcs 4703e Firmware HIGH 8.8
CVE-2020-25079 KEVEPSS 53%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated comma…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
Dcs 4603 Firmware HIGH 7.5
CVE-2020-25078 KEVEPSS 98%

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint al…

Fix: 1.03.02 / 1.03.04+
Fix from $1,950 2020-09-02
Dir 842 Firmware HIGH 8.8
CVE-2020-15632

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers. Authentica…

Fix: after 3.13b09
Fix from $1,950 2020-07-23
Dap 1860 Firmware HIGH 8.0
CVE-2020-15631

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi exten…

Fix: after 1.04b01
Fix from $1,950 2020-07-23
Dap 1520 Firmware CRITICAL 9.8
CVE-2020-15892

An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login action from the web interface,…

Fix: after 1.10b04
Fix from $2,300 2020-07-22
Dir 816l Firmware CRITICAL 9.8
CVE-2020-15893EPSS 21%

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An at…

Patch available
Fix from $2,300 2020-07-22
Dir 816l Firmware HIGH 7.5
CVE-2020-15894

An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can…

Patch available
Fix from $1,950 2020-07-22
Dap 1522 Firmware HIGH 7.5
CVE-2020-15896

An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pages that are directly accessi…

Patch available
Fix from $1,950 2020-07-22