Vulnerability index

Browse CVEs

96 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dvg G5402sp Firmware CRITICAL 9.8
CVE-2022-44929

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profil…

No fix yet
Fix from $2,300 2022-12-02
Dvg G5402sp Firmware CRITICAL 9.8
CVE-2022-44928

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

No fix yet
Fix from $2,300 2022-12-02
Dir 868lw Firmware MEDIUM 5.3
CVE-2021-33259

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query hi…

No fix yet
Fix from $1,600 2021-10-31
Dsl 320b D1 CRITICAL 9.8
CVE-2021-26709EPSS 40%

D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take ove…

No fix yet
Fix from $2,300 2021-04-07
Dir 822 Firmware CRITICAL 9.8
CVE-2019-6258

D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP prot…

Fix: after 2.02krb06
Fix from $2,300 2020-08-18
Dir 867 Firmware HIGH 8.8
CVE-2020-15633

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 route…

Fix: after 1.20b10
Fix from $1,950 2020-07-23
Dsl 2640b Firmware HIGH 7.5
CVE-2020-9544

An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-upd…

No fix yet
Fix from $1,950 2020-03-05
Dsl6740u Firmware HIGH 8.8
CVE-2013-6811

Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authenticat…

Mitigation only
Fix from $1,950 2019-11-22
Dir 866l Firmware MEDIUM 6.1
CVE-2019-17663

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

Mitigation only
Fix from $1,600 2019-10-16
Dir 818lw Firmware CRITICAL 9.8
CVE-2018-19986EPSS 42%

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DI…

No fix yet
Fix from $2,300 2019-05-13
Dir 818lw Firmware CRITICAL 9.8
CVE-2018-19987EPSS 13%

D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-8…

No fix yet
Fix from $2,300 2019-05-13
Dir 868l Firmware CRITICAL 9.8
CVE-2018-19988EPSS 7%

In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.…

No fix yet
Fix from $2,300 2019-05-13
Dir 822 Firmware CRITICAL 9.8
CVE-2018-19989EPSS 6%

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev…

No fix yet
Fix from $2,300 2019-05-13
Dir 822 Firmware CRITICAL 9.8
CVE-2018-19990EPSS 5%

In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices. In th…

No fix yet
Fix from $2,300 2019-05-13
Dap 1530 Firmware CRITICAL 9.8
CVE-2018-19300EPSS 74%

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02,…

Fix: after 2.02
Fix from $2,300 2019-04-11
Dir 878 Firmware CRITICAL 9.8
CVE-2019-9124

An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.

No fix yet
Fix from $2,300 2019-02-25
Dir 878 Firmware CRITICAL 9.8
CVE-2019-9125

An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does…

No fix yet
Fix from $2,300 2019-02-25
Dir 823g Firmware CRITICAL 9.8
CVE-2019-7297EPSS 12%

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbit…

Fix: after 1.02b03
Fix from $2,300 2019-01-31
Dcm 604 Firmware CRITICAL 9.8
CVE-2018-20389

D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4…

No fix yet
Fix from $2,300 2018-12-23
Dcs 936l Firmware HIGH 7.5
CVE-2018-18441

D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, suc…

No fix yet
Fix from $1,950 2018-12-20
Dcs 825l Firmware HIGH 7.5
CVE-2018-18442

D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the de…

No fix yet
Fix from $1,950 2018-12-20
Dir 816 A2 Firmware CRITICAL 9.8
CVE-2018-20305

D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userco…

No fix yet
Fix from $2,300 2018-12-20
Dir 619l Firmware CRITICAL 9.8
CVE-2018-20056EPSS 7%

An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowin…

No fix yet
Fix from $2,300 2018-12-11
Dir 619l Firmware HIGH 8.8
CVE-2018-20057EPSS 7%

An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated …

No fix yet
Fix from $1,950 2018-12-11
Dsl 2640t Firmware MEDIUM 6.1
CVE-2018-18636

XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.

No fix yet
Fix from $1,600 2018-10-24
Dir 809 A1 Firmware CRITICAL 9.8
CVE-2018-14081

An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin …

Fix: after 1.11
Fix from $2,300 2018-10-09
Dir 809 A1 Firmware HIGH 7.5
CVE-2018-14080

An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechan…

Fix: after 1.11
Fix from $1,950 2018-10-09
Dir 823g Firmware CRITICAL 9.8
CVE-2018-17881

On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin …

No fix yet
Fix from $2,300 2018-10-03
Dir 823g Firmware HIGH 7.5
CVE-2018-17880

On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a reboot.

No fix yet
Fix from $1,950 2018-10-03
Dir 823g Firmware CRITICAL 9.8
CVE-2018-17786

On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, whic…

No fix yet
Fix from $2,300 2018-10-02