Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28
CVSS Score
9.8
EPSS Score
0.679
Published
2023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data function.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.
CVSS Score
9.8
EPSS Score
0.009
Published
2023-09-20
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.
CVSS Score
9.8
EPSS Score
0.023
Published
2023-09-20
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-09-20
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows attackers to execute arbitrary commands via the manual-time-string parameter.
CVSS Score
9.8
EPSS Score
0.023
Published
2023-09-20
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnerability allows attackers to execute arbitrary commands via the certDownload parameter.
CVSS Score
9.8
EPSS Score
0.023
Published
2023-09-20
D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerability allows attackers to execute arbitrary commands via the configRestore parameter.
CVSS Score
9.8
EPSS Score
0.023
Published
2023-09-20
D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp function.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.asp function.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-09-20


Contact Us

Shodan ® - All rights reserved