Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dcs 2102 Firmware MEDIUM 5.3
CVE-2013-1600EPSS 19%

An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_…

No fix yet
Fix from $1,600 2020-01-28
Dcs 3411 Firmware MEDIUM 5.3
CVE-2013-1601EPSS 13%

An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LI…

No fix yet
Fix from $1,600 2020-01-28
Dcs 3411 Firmware CRITICAL 9.8
CVE-2013-1599EPSS 40%

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01…

No fix yet
Fix from $2,300 2020-01-28
Dsr 250n Firmware HIGH 7.2
CVE-2012-6613

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

No fix yet
Fix from $1,950 2020-01-25
Dcs 935l Firmware CRITICAL 9.8
CVE-2019-17146EPSS 10%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not re…

Fix: after 1.12.101
Fix from $2,300 2020-01-07
Dir 859 Firmware HIGH 7.5
CVE-2019-20213

D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnc…

Fix: after 3.12b04
Fix from $1,950 2020-01-02
Dgs 1510 20 Firmware MEDIUM 6.1
CVE-2018-7859

A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to…

Fix: after 1.31.b003
Fix from $1,600 2019-12-30
Dir 859 Firmware CRITICAL 9.8
CVE-2019-17621 KEVEPSS 90%

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute syste…

Fix: after 3.12b04
Fix from $2,300 2019-12-30
Dwr 113 Firmware HIGH 8.8
CVE-2014-3136

Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authen…

Fix: 2.03b02+
Fix from $1,950 2019-12-27
Dir 601 Firmware CRITICAL 9.8
CVE-2019-16327

D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-…

No fix yet
Fix from $2,300 2019-12-26
Dir 601 Firmware HIGH 8.8
CVE-2019-16326

D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-20…

No fix yet
Fix from $1,950 2019-12-26
Dba 1510p Firmware HIGH 8.8
CVE-2019-6014

DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.

Fix: after 1.70b009
Fix from $1,950 2019-12-26
Dba 1510p Firmware MEDIUM 6.6
CVE-2019-6013

DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).

Fix: after 1.70b009
Fix from $1,600 2019-12-26
Dir 615 T1 Firmware MEDIUM 6.5
CVE-2019-19743EPSS 9%

On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

No fix yet
Fix from $1,600 2019-12-16
Dap 1860 Firmware HIGH 8.8
CVE-2019-19597EPSS 21%

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an …

No fix yet
Fix from $1,950 2019-12-05
Dap 1860 Firmware HIGH 8.8
CVE-2019-19598

D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value.…

No fix yet
Fix from $1,950 2019-12-05
Dir 600 B1 Firmware CRITICAL 9.8
CVE-2019-18852

Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_si…

No fix yet
Fix from $2,300 2019-11-11
Dir 865l Firmware CRITICAL 9.8
CVE-2013-4857

D-Link DIR-865L has PHP File Inclusion in the router xml file.

No fix yet
Fix from $2,300 2019-10-25
Dir 865l Firmware HIGH 8.8
CVE-2013-4855

D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of th…

Mitigation only
Fix from $1,950 2019-10-25
Dir 865l Firmware MEDIUM 6.5
CVE-2013-4856

D-Link DIR-865L has Information Disclosure.

No fix yet
Fix from $1,600 2019-10-25
Dir 412 Firmware CRITICAL 9.1
CVE-2019-17512

There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file vi…

No fix yet
Fix from $2,300 2019-10-16
Dir 868l Firmware CRITICAL 9.8
CVE-2017-14948

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary cod…

No fix yet
Fix from $2,300 2019-10-14
Dir 412 Firmware HIGH 7.5
CVE-2019-17511

There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via …

No fix yet
Fix from $1,950 2019-10-14
Dir 868l B1 Firmware CRITICAL 9.8
CVE-2019-17506EPSS 56%

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the r…

No fix yet
Fix from $2,300 2019-10-11
Dir 859 A3 Firmware CRITICAL 9.8
CVE-2019-17508EPSS 16%

On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.

No fix yet
Fix from $2,300 2019-10-11
Dir 846 Firmware CRITICAL 9.8
CVE-2019-17509

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a …

No fix yet
Fix from $2,300 2019-10-11
Dir 846 Firmware CRITICAL 9.8
CVE-2019-17510

D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a …

No fix yet
Fix from $2,300 2019-10-11
Dir 816 A1 Firmware HIGH 7.5
CVE-2019-17507

An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a client that ignores the 'top…

No fix yet
Fix from $1,950 2019-10-11
Dap 1320 A2 Firmware HIGH 7.5
CVE-2019-17505

D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can re…

No fix yet
Fix from $1,950 2019-10-11
Dir 615 Firmware HIGH 8.2
CVE-2019-17353

An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which c…

Mitigation only
Fix from $1,950 2019-10-09