Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.
CVSS Score
9.8
EPSS Score
0.144
Published
2022-06-02
D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
CVSS Score
9.8
EPSS Score
0.012
Published
2022-05-23
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.
CVSS Score
7.5
EPSS Score
0.397
Published
2022-05-18
An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.
CVSS Score
9.8
EPSS Score
0.227
Published
2022-05-18
D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.
CVSS Score
6.5
EPSS Score
0.014
Published
2022-05-17
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
CVSS Score
9.8
EPSS Score
0.067
Published
2022-05-10
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.
CVSS Score
9.8
EPSS Score
0.039
Published
2022-05-10
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.
CVSS Score
9.8
EPSS Score
0.169
Published
2022-05-10
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.
CVSS Score
9.8
EPSS Score
0.039
Published
2022-05-10
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.
CVSS Score
9.8
EPSS Score
0.039
Published
2022-05-10


Contact Us

Shodan ® - All rights reserved