Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 825 Firmware HIGH 8.8
CVE-2020-10215EPSS 5%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parame…

No fix yet
Fix from $1,950 2020-03-07
Dir 825 Firmware HIGH 8.8
CVE-2020-10216EPSS 5%

An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a s…

No fix yet
Fix from $1,950 2020-03-07
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20499EPSS 95%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the …

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20500 KEVEPSS 97%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web…

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Dwl 2600ap Firmware HIGH 7.8
CVE-2019-20501EPSS 90%

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web i…

Fix: after 4.2.0.15
Fix from $1,950 2020-03-05
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19224

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to download the confi…

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19225

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to change DNS servers…

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19226

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to enable or disable …

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware HIGH 7.5
CVE-2019-19223

A Broken Access Control vulnerability in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an attacker to reboot the router …

No fix yet
Fix from $1,950 2020-03-04
Dsl 2680 Firmware MEDIUM 5.4
CVE-2019-19222

A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attacker to inject arbitrary JavaSc…

No fix yet
Fix from $1,600 2020-03-04
Dir 615jx10 Firmware HIGH 8.8
CVE-2020-9534

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed.

No fix yet
Fix from $1,950 2020-03-02
Dir 615jx10 Firmware HIGH 8.8
CVE-2020-9535

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malforme…

No fix yet
Fix from $1,950 2020-03-02
Dap 1330 Firmware HIGH 8.8
CVE-2020-8861EPSS 7%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range e…

Fix: 1.10b01+
Fix from $1,950 2020-02-22
Dap 2610 Firmware HIGH 8.8
CVE-2020-8862EPSS 13%

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 router…

Fix: after 2.01rc067
Fix from $1,950 2020-02-22
Dch M225 Firmware CRITICAL 9.8
CVE-2020-6841

D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.ph…

Fix: after 1.05b01
Fix from $2,300 2020-02-21
Dch M225 Firmware HIGH 7.2
CVE-2020-6842

D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media …

Fix: after 1.05b01
Fix from $1,950 2020-02-21
Dsr 250n Firmware HIGH 7.2
CVE-2012-6614

D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by ov…

Fix: 1.08b31+
Fix from $1,950 2020-02-19
Dir 842 Firmware CRITICAL 9.8
CVE-2020-8962

A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when hand…

No fix yet
Fix from $2,300 2020-02-13
Dsr 150 Firmware CRITICAL 9.8
CVE-2013-5945EPSS 10%

Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N wi…

Fix: 1.05b64 / 1.08b44+
Fix from $2,300 2020-02-11
Dir865l Firmware MEDIUM 5.9
CVE-2013-3096

D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.

No fix yet
Fix from $1,600 2020-02-07
Dir 100 Firmware CRITICAL 9.8
CVE-2013-7055EPSS 7%

D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

No fix yet
Fix from $2,300 2020-02-04
Dir 100 Firmware MEDIUM 6.1
CVE-2013-7054

D-Link DIR-100 4.03B07: cli.cgi XSS

No fix yet
Fix from $1,600 2020-02-04
Dir 100 Firmware CRITICAL 9.8
CVE-2013-7052EPSS 25%

D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

No fix yet
Fix from $2,300 2020-02-04
Dir 100 Firmware HIGH 8.8
CVE-2013-7051EPSS 16%

D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

No fix yet
Fix from $1,950 2020-02-04
Dir 100 Firmware HIGH 8.8
CVE-2013-7053

D-Link DIR-100 4.03B07: cli.cgi CSRF

No fix yet
Fix from $1,950 2020-02-04
Dir 859 Firmware CRITICAL 9.8
CVE-2019-20215EPSS 75%

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi()…

Patch available
Fix from $2,300 2020-01-29
Dir 859 Firmware CRITICAL 9.8
CVE-2019-20216

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi…

Patch available
Fix from $2,300 2020-01-29
Dir 859 Firmware CRITICAL 9.8
CVE-2019-20217

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi…

Patch available
Fix from $2,300 2020-01-29
Dcs 3411 Firmware HIGH 7.5
CVE-2013-1602EPSS 15%

An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01,…

No fix yet
Fix from $1,950 2020-01-28
Dcs 3411 Firmware MEDIUM 5.3
CVE-2013-1603EPSS 16%

An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, D…

No fix yet
Fix from $1,600 2020-01-28