Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 816l Firmware MEDIUM 6.1
CVE-2020-15895

An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to t…

Patch available
Fix from $1,600 2020-07-22
Dsl 7740c Firmware MEDIUM 6.7
CVE-2020-12774

D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.

Mitigation only
Fix from $1,600 2020-07-22
Dir 610 Firmware HIGH 8.8
CVE-2020-9377 KEVEPSS 21%

D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are n…

Patch available
Fix from $1,950 2020-07-09
Dir 610 Firmware HIGH 7.5
CVE-2020-9376EPSS 17%

D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE: This vulnerability only aff…

Patch available
Fix from $1,950 2020-07-09
Dsl 2750u Firmware HIGH 7.8
CVE-2020-13150

D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…

Mitigation only
Fix from $1,950 2020-06-15
Dsl 2730u Firmware HIGH 7.5
CVE-2020-13960

D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows …

No fix yet
Fix from $1,950 2020-06-08
Dir 865l Firmware HIGH 8.8
CVE-2020-13786

D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13783

D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13784

D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13785

D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 7.5
CVE-2020-13787

D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.

No fix yet
Fix from $1,950 2020-06-03
Dir 865l Firmware HIGH 8.8
CVE-2020-13782EPSS 27%

D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

No fix yet
Fix from $1,950 2020-06-03
Dsp W215 Firmware HIGH 7.5
CVE-2020-13136

D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.

Mitigation only
Fix from $1,950 2020-05-18
Dsp W215 Firmware MEDIUM 6.5
CVE-2020-13135

D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy.

Mitigation only
Fix from $1,600 2020-05-18
Dap 1360 Revision F Firmware CRITICAL 9.8
CVE-2019-18666

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented …

Fix: after 6.12b01
Fix from $2,300 2020-05-15
Dir 615 Firmware HIGH 8.8
CVE-2019-17525EPSS 6%

The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.

No fix yet
Fix from $1,950 2020-04-21
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9275

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltratio…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9277

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perfor…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9279

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The log…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware CRITICAL 9.1
CVE-2020-9278

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated…

No fix yet
Fix from $2,300 2020-04-20
Dsl 2640b Firmware HIGH 8.8
CVE-2020-9276

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests supplied to the device's web ser…

No fix yet
Fix from $1,950 2020-04-20
Dsl Gs225 Firmware HIGH 7.2
CVE-2020-6765

D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstr…

Patch available
Fix from $1,950 2020-04-10
Dir 878 Firmware HIGH 8.8
CVE-2020-8863EPSS 77%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 route…

Fix: after 1.20b03
Fix from $1,950 2020-03-23
Dir 878 Firmware HIGH 8.8
CVE-2020-8864EPSS 80%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 route…

Fix: after 1.20b03
Fix from $1,950 2020-03-23
Dap 1650 Firmware CRITICAL 9.8
CVE-2019-12767

An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.

Fix: 1.04b02_j65h+
Fix from $2,300 2020-03-21
Dsl 2875al Firmware HIGH 7.5
CVE-2019-15655

D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. Th…

Fix: after 1.00.05
Fix from $1,950 2020-03-19
Dsl 2875al Firmware HIGH 7.5
CVE-2019-15656

D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web man…

Fix: after 1.00.05
Fix from $1,950 2020-03-19
Dcs 930l Firmware HIGH 7.2
CVE-2016-11021 KEVEPSS 69%

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

Fix: 2.12+
Fix from $1,950 2020-03-09
Dir 825 Firmware HIGH 8.8
CVE-2020-10213

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin …

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10214EPSS 18%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated …

No fix yet
Fix from $1,950 2020-03-07