Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dwr 116 Firmware HIGH 8.8
CVE-2018-10823EPSS 78%

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and D…

Fix: after 2.02
Fix from $1,950 2018-10-17
Dwr 116 Firmware HIGH 7.5
CVE-2018-10822EPSS 39%

Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through …

Fix: after 2.02
Fix from $1,950 2018-10-17
Central Wifimanager HIGH 8.8
CVE-2018-17442EPSS 14%

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endp…

Fix: 1.03+
Fix from $1,950 2018-10-08
Central Wifimanager MEDIUM 6.1
CVE-2018-17443EPSS 6%

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to…

Fix: after 1.03
Fix from $1,600 2018-10-08
Central Wifimanager CRITICAL 9.8
CVE-2018-17440EPSS 38%

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and ha…

Fix: 1.03+
Fix from $2,300 2018-10-08
Central Wifimanager MEDIUM 6.1
CVE-2018-17441EPSS 6%

An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to st…

Fix: after 1.03
Fix from $1,600 2018-10-08
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17063

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17064EPSS 7%

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler fu…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17065

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17066EPSS 7%

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi…

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17067

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow …

No fix yet
Fix from $2,300 2018-09-15
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-17068

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler functi…

No fix yet
Fix from $2,300 2018-09-15
Dir 600m Firmware MEDIUM 5.4
CVE-2018-16605

D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.

No fix yet
Fix from $1,600 2018-09-12
Dir 601 Firmware HIGH 8.0
CVE-2018-12710EPSS 77%

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account…

No fix yet
Fix from $1,950 2018-08-29
Dir 615 Firmware CRITICAL 9.8
CVE-2018-15839EPSS 45%

D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.

No fix yet
Fix from $2,300 2018-08-28
Dir 615 Firmware MEDIUM 6.1
CVE-2018-15874

Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Ta…

Mitigation only
Fix from $1,600 2018-08-25
Dir 615 Firmware MEDIUM 6.1
CVE-2018-15875

Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via …

Mitigation only
Fix from $1,600 2018-08-25
Eyeon Baby Monitor Firmware CRITICAL 9.8
CVE-2017-11563EPSS 5%

D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has a remote code execution vulnerability. A UDP "Discover" service, which provides multiple functions su…

Mitigation only
Fix from $2,300 2018-08-24
Eyeon Baby Monitor Firmware HIGH 8.8
CVE-2017-11564

The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge ma…

Mitigation only
Fix from $1,950 2018-08-24
Dir 823 Firmware CRITICAL 9.8
CVE-2016-6563EPSS 80%

Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulner…

No fix yet
Fix from $2,300 2018-07-13
Dir 890l Firmware MEDIUM 6.5
CVE-2018-12103

An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/…

Fix: after 1.21b04beta01
Fix from $1,600 2018-07-05
Dir 620 Firmware CRITICAL 9.8
CVE-2018-6210

D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attac…

Mitigation only
Fix from $2,300 2018-06-19
Dsl 3782 Firmware CRITICAL 9.8
CVE-2018-8898EPSS 13%

A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer…

No fix yet
Fix from $2,300 2018-05-23
Dir 868l Firmware HIGH 8.8
CVE-2018-10957

CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affecte…

No fix yet
Fix from $1,950 2018-05-10
Dir 601 Firmware HIGH 8.1
CVE-2018-10641

D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.

No fix yet
Fix from $1,950 2018-05-04
Dcs 5009 Firmware HIGH 8.8
CVE-2017-17020EPSS 15%

On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware…

Fix: after 1.14.09
Fix from $1,950 2018-05-01
Dir 815 Firmware CRITICAL 9.8
CVE-2018-10106

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdo…

Fix: after 2.07.b01
Fix from $2,300 2018-04-16
Dir 815 Firmware MEDIUM 6.1
CVE-2018-10107

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info…

Fix: after 2.07.b01
Fix from $1,600 2018-04-16
Dir 815 Firmware MEDIUM 6.1
CVE-2018-10108

D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc…

Fix: after 2.07.b01
Fix from $1,600 2018-04-16
Dir 815 Firmware CRITICAL 9.8
CVE-2014-8888EPSS 5%

The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via…

Mitigation only
Fix from $2,300 2018-04-12