Vulnerabilities
Vulnerable Software
Dlink:  Security Vulnerabilities
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
CVSS Score
7.5
EPSS Score
0.039
Published
2017-01-30
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
CVSS Score
9.8
EPSS Score
0.087
Published
2017-01-30
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
CVSS Score
7.5
EPSS Score
0.056
Published
2017-01-30
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
CVSS Score
7.5
EPSS Score
0.056
Published
2017-01-30
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
CVSS Score
7.5
EPSS Score
0.042
Published
2017-01-30
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.
CVSS Score
7.5
EPSS Score
0.042
Published
2017-01-30
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.
CVSS Score
8.1
EPSS Score
0.012
Published
2017-01-09
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.
CVSS Score
9.8
EPSS Score
0.119
Published
2016-08-25
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.
CVSS Score
6.8
EPSS Score
0.032
Published
2015-11-18
CVE-2014-8361
Known exploited
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
CVSS Score
9.8
EPSS Score
1.0
Published
2015-05-01


Contact Us

Shodan ® - All rights reserved