Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-09-20
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/login.cgi function.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-09-20
D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.
CVSS Score
9.8
EPSS Score
0.03
Published
2023-09-14
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
CVSS Score
9.8
EPSS Score
0.017
Published
2023-09-12
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
CVSS Score
9.8
EPSS Score
0.008
Published
2023-09-11
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
CVSS Score
9.8
EPSS Score
0.009
Published
2023-09-11
An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required
CVSS Score
7.5
EPSS Score
0.01
Published
2023-09-11
Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows authorized attackers execute arbitrary code via sending crafted data to the webserver service program.
CVSS Score
8.8
EPSS Score
0.01
Published
2023-09-11
A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230819. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-238574 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
5.0
EPSS Score
0.058
Published
2023-09-01
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
6.3
EPSS Score
0.878
Published
2023-08-25


Contact Us

Shodan ® - All rights reserved