Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
CVSS Score
9.8
EPSS Score
0.146
Published
2021-02-02
CVE-2020-25506
Known exploited
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
CVSS Score
9.8
EPSS Score
1.0
Published
2021-02-02
CVE-2020-29557
Known exploited
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.
CVSS Score
9.8
EPSS Score
0.543
Published
2021-01-29
D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS Score
8.0
EPSS Score
0.009
Published
2021-01-19
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin login password and the Internet provider connection username and cleartext password, in the application's response body for a /tmp/var/passwd or /tmp/home/wan_stat URI.
CVSS Score
7.5
EPSS Score
0.191
Published
2021-01-08
An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.
CVSS Score
9.8
EPSS Score
0.023
Published
2020-12-30
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).
CVSS Score
6.5
EPSS Score
0.018
Published
2020-12-22
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
CVSS Score
8.8
EPSS Score
0.1
Published
2020-12-22
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.
CVSS Score
7.5
EPSS Score
0.013
Published
2020-12-22
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.
CVSS Score
8.0
EPSS Score
0.137
Published
2020-12-22


Contact Us

Shodan ® - All rights reserved