Dlink
dlink
1,708 CVEs • 918 products
Products (918)
Click to collapseToggle
Products (918)
Click to collapse
CVEs (1,708)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dlink 14Dir 818lx Firmware Dir 822 FirmwareDir 823 Firmware+11 moreJun 17, 2026 Jan 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php. |
1Dlink 8Dgs 1510 20 Firmware Dgs 1510 28 FirmwareDgs 1510 28p Firmware+5 moreJun 17, 2026 Dec 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to inject malicious scripts in the device and execute commands via browse...Show more |
1Dlink 14Dir 818lx Firmware Dir 822 FirmwareDir 823 Firmware+11 moreJun 17, 2026 Dec 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE reque...Show more |
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password...Show more |
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life prod...Show more |
D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit this in conjunction with CVE-2019-16327 to enable remote router management and device compromise. NOTE...Show more |
DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface. |
DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI). |
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. |
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal. |
D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used t...Show more |
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header. |
1Dlink 7Dir 600 B1 Firmware Dir 615 J1 FirmwareDir 645 A1 Firmware+4 moreJun 17, 2026 Nov 11, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1...Show more |
D-Link DIR-865L has PHP File Inclusion in the router xml file. |
D-Link DIR-865L has Information Disclosure. |
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share. |
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can clear the router's log file via act=clear&logtype=sysact to log_clear.php, which could be used to era...Show more |
1Dlink 6Dir 868l Firmware Dir 880l FirmwareDir 885l Firmware+3 moreNov 21, 2024 Oct 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector...Show more |
There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network struc...Show more |
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squas...Show more |