Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fi range extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper handling of cookies. An attacker can leverage this vulnerability to execute arbitrary code on the router. Was ZDI-CAN-9554.
CVSS Score
8.8
EPSS Score
0.065
Published
2020-02-22
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from the lack of proper password checking. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-10082.
CVSS Score
8.8
EPSS Score
0.133
Published
2020-02-22
D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.
CVSS Score
9.8
EPSS Score
0.028
Published
2020-02-21
D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.
CVSS Score
7.2
EPSS Score
0.023
Published
2020-02-21
D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.
CVSS Score
7.2
EPSS Score
0.034
Published
2020-02-19
A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when handling a POST request to the /MTFWU endpoint.
CVSS Score
9.8
EPSS Score
0.018
Published
2020-02-13
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.
CVSS Score
9.8
EPSS Score
0.098
Published
2020-02-11
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
CVSS Score
5.9
EPSS Score
0.013
Published
2020-02-07
D-Link DIR-100 4.03B07: cli.cgi XSS
CVSS Score
6.1
EPSS Score
0.035
Published
2020-02-04
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
CVSS Score
9.8
EPSS Score
0.07
Published
2020-02-04


Contact Us

Shodan ® - All rights reserved