Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
CVSS Score
7.5
EPSS Score
0.014
Published
2022-04-10
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
CVSS Score
7.5
EPSS Score
0.014
Published
2022-04-10
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.
CVSS Score
7.5
EPSS Score
0.014
Published
2022-04-10
An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function
CVSS Score
9.8
EPSS Score
0.031
Published
2022-04-07
D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.
CVSS Score
8.8
EPSS Score
0.015
Published
2022-04-07
D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.
CVSS Score
9.8
EPSS Score
0.032
Published
2022-03-31
CVE-2022-26258
Known exploited
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVSS Score
9.8
EPSS Score
0.804
Published
2022-03-28
In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.
CVSS Score
9.8
EPSS Score
0.034
Published
2022-03-27
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.
CVSS Score
9.8
EPSS Score
0.022
Published
2022-03-24
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.
CVSS Score
5.3
EPSS Score
0.022
Published
2022-03-04


Contact Us

Shodan ® - All rights reserved