Vulnerability index

Browse CVEs

1,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 850l Firmware MEDIUM 6.1
CVE-2017-14414

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php.

No fix yet
Fix from $1,600 2017-09-13
Dir 850l Firmware MEDIUM 6.1
CVE-2017-14415

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.

No fix yet
Fix from $1,600 2017-09-13
Dir 850l Firmware MEDIUM 6.1
CVE-2017-14416

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.

No fix yet
Fix from $1,600 2017-09-13
Dir 850l Firmware MEDIUM 5.9
CVE-2017-14419

The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW…

No fix yet
Fix from $1,600 2017-09-13
Dir 850l Firmware MEDIUM 5.9
CVE-2017-14420

The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WW…

No fix yet
Fix from $1,600 2017-09-13
Dir 600 B1 Firmware CRITICAL 9.8
CVE-2017-12943EPSS 39%

D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path tra…

No fix yet
Fix from $2,300 2017-08-18
Dir 615 CRITICAL 9.8
CVE-2017-11436

D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TEL…

Fix: after 20.12ptb01
Fix from $2,300 2017-07-19
Dir 615 CRITICAL 9.8
CVE-2017-7405

On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the…

Fix: after 20.12ptb01
Fix from $2,300 2017-07-07
Dir 615 CRITICAL 9.8
CVE-2017-7406

The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own …

Fix: after 20.12ptb01
Fix from $2,300 2017-07-07
Dir 615 HIGH 8.8
CVE-2017-7404

On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the m…

Fix: after 20.12ptb01
Fix from $1,950 2017-07-07
Dir 605l Firmware HIGH 7.5
CVE-2017-9675EPSS 12%

On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.

No fix yet
Fix from $1,950 2017-06-15
Dir 600m Firmware HIGH 8.8
CVE-2017-9100EPSS 85%

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the…

No fix yet
Fix from $1,950 2017-05-21
Dcs 2230l Firmware HIGH 8.8
CVE-2017-7852

D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s…

Fix: after 2.13.15
Fix from $1,950 2017-04-24
Dap 3662 Firmware CRITICAL 9.8
CVE-2016-1558EPSS 9%

Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP…

Patch available
Fix from $2,300 2017-04-21
Dwr 116 Firmware HIGH 7.5
CVE-2017-6190EPSS 18%

Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arb…

No fix yet
Fix from $1,950 2017-04-10
Dsl 2730u Firmware HIGH 8.8
CVE-2017-6411

Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any p…

No fix yet
Fix from $1,950 2017-03-06
Websmart Dgs 1510 Series Firmware CRITICAL 9.8
CVE-2017-6205

D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31…

Fix: after 1.31.b001
Fix from $2,300 2017-02-23
Websmart Dgs 1510 Series Firmware HIGH 7.5
CVE-2017-6206EPSS 16%

D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31…

Fix: after 1.31.b001
Fix from $1,950 2017-02-23
Dwr 932b Firmware CRITICAL 9.8
CVE-2016-10177EPSS 7%

An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root …

No fix yet
Fix from $2,300 2017-01-30
Dwr 932b Firmware CRITICAL 9.8
CVE-2016-10178EPSS 7%

An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.

No fix yet
Fix from $2,300 2017-01-30
Dwr 932b Firmware CRITICAL 9.8
CVE-2016-10182EPSS 9%

An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

No fix yet
Fix from $2,300 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10179

An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10180

An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10181

An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10183EPSS 6%

An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10184EPSS 6%

An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10185

An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.

No fix yet
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10186

An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.

No fix yet
Fix from $1,950 2017-01-30
Dgs 1100 Firmware HIGH 8.1
CVE-2016-10125

D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by h…

No fix yet
Fix from $1,950 2017-01-09
Dir 868l Firmware CRITICAL 9.8
CVE-2016-5681EPSS 12%

Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3…

Fix: after 3.00
Fix from $2,300 2016-08-25