CVEs (19)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ subma...Show more |
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr leads to os command inject...Show more |
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command in...Show more |
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can b...Show more |
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipadd...Show more |
1Dlink 7Dir 110 Firmware Dir 412 FirmwareDir 600 Firmware+4 moreSep 24, 2025 Aug 27, 2025 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to e...Show more |
1Dlink 2Dir 300 Firmware Dir 615 FirmwareMay 26, 2026 Aug 1, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly san...Show more |
1Dlink 44Dap 1360 Firmware Dir 1210 FirmwareDir 1260 Firmware+41 moreJun 17, 2026 Jan 19, 2024 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825...Show more |
1Dlink 4Dir 615 Firmware Dir 615 J1 FirmwareDir 615 T1 Firmware+1 moreJul 9, 2026 Aug 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker...Show more |
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page |
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution. |
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. |
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. |
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be lev...Show more |
1Dlink 10Dap 1533 Firmware Dhp 1565 FirmwareDir 615 Firmware+7 moreJun 17, 2026 Sep 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interfa...Show more |
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. |
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request. |
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request. |
3Aterm DlinkRealtek26Dir 501 Firmware Dir 515 FirmwareDir 600l Firmware+23 moreApr 22, 2026 May 1, 2015 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. |