Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequence.
CVSS Score
5.5
EPSS Score
0.008
Published
2019-08-01
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication admin.cgi?action= XSS vulnerability on the management interface.
CVSS Score
6.1
EPSS Score
0.02
Published
2019-08-01
An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-group1-sha1.
CVSS Score
7.8
EPSS Score
0.014
Published
2019-08-01
D-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE: Third parties dispute this issues as not being a vulnerability because although the wizard is accessible without authentication, it can't actually configure anything. Thus, there is no denial of service or information leakage
CVSS Score
9.1
EPSS Score
0.086
Published
2019-07-23
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.
CVSS Score
9.8
EPSS Score
0.036
Published
2019-07-11
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
CVSS Score
9.8
EPSS Score
0.084
Published
2019-07-11
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_sec.cgi html_response_return_page parameter.
CVSS Score
6.1
EPSS Score
0.018
Published
2019-07-11
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
CVSS Score
8.8
EPSS Score
0.01
Published
2019-07-11
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.
CVSS Score
8.8
EPSS Score
0.082
Published
2019-07-10
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings.
CVSS Score
8.8
EPSS Score
0.081
Published
2019-07-10


Contact Us

Shodan ® - All rights reserved