D-Link records
115 published records for vendor d-link.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 22
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')14
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer12
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-287 Improper Authentication7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
The weakness classes this vendor ships most often: where to look.
CWEAll records
115 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2018-19300No exploit | On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware versiond-link · dap-1530 firmware · CWE-20 | Critical9.8 | — | 74.3% | Apr 11, 2019 |
58Plan | CVE-2017-3191No exploit | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.d-link · dir-130 firmware · CWE-294 | Critical9.8 | — | 62.5% | Dec 15, 2017 |
53Plan | CVE-2007-1435Weaponized | Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT requestd-link · tftp server | Critical10.0 | — | 42.8% | Mar 13, 2007 |
51Plan | CVE-2018-19986No exploit | In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.Bd-link · dir-818lw firmware · CWE-78 | Critical9.8 | — | 41.6% | May 13, 2019 |
51Plan | CVE-2021-26709No exploit | D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers tod-link · dsl-320b-d1 · CWE-787 | Critical9.8 | — | 40.1% | Apr 7, 2021 |
51Plan | CVE-2017-3192No exploit | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.d-link · dir-130 firmware · CWE-522 | Critical9.8 | — | 39.5% | Dec 15, 2017 |
48Plan | CVE-2018-5371No exploit | diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticatd-link · dsl-2540u firmware · CWE-78 | High8.8 | — | 42.0% | Jan 12, 2018 |
45Plan | CVE-2014-7859No exploit | Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-32d-link · dns-322l firmware · CWE-119 | Critical9.8 | — | 20.9% | Aug 25, 2017 |
44Plan | CVE-2015-7245Proof of concept | Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read d-link · dvg-n5402sp firmware · CWE-22 | High7.5 | — | 45.5% | Apr 24, 2017 |
44Plan | CVE-2014-7857No exploit | D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05d-link · dns-322l firmware · CWE-287 | Critical9.8 | — | 15.2% | Aug 25, 2017 |
44Plan | CVE-2014-7858No exploit | The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the ud-link · dnr-326 firmware · CWE-287 | Critical9.8 | — | 15.2% | Aug 25, 2017 |
43Plan | CVE-2015-7246Proof of concept | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the twd-link · dvg-n5402sp firmware · CWE-798 | Critical9.8 | — | 14.3% | Apr 24, 2017 |
43Plan | CVE-2018-19987Proof of concept | D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, d-link · dir-818lw firmware · CWE-78 | Critical9.8 | — | 12.9% | May 13, 2019 |
43Plan | CVE-2019-7297No exploit | An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03.d-link · dir-823g firmware · CWE-78 | Critical9.8 | — | 12.5% | Jan 31, 2019 |
43Plan | CVE-2016-5681No exploit | Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIRd-link · dir-880l firmware · CWE-119 | Critical9.8 | — | 11.9% | Aug 25, 2016 |
42Plan | CVE-2015-7247Proof of concept | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes d-link · dvg-n5402sp firmware · CWE-200 | Critical9.8 | — | 10.2% | Apr 24, 2017 |
42Plan | CVE-2006-6055Proof of concept | Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary coded-link · dwl-g132 | Critical10.0 | — | 5.9% | Nov 21, 2006 |
41Plan | CVE-2018-19988No exploit | In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-d-link · dir-868l firmware · CWE-78 | Critical9.8 | — | 7.4% | May 13, 2019 |
41Plan | CVE-2018-20056No exploit | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices.d-link · dir-619l firmware · CWE-787 | Critical9.8 | — | 7.0% | Dec 11, 2018 |
41Plan | CVE-2018-11013No exploit | Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows ud-link · dir-816 a2 firmware · CWE-787 | Critical9.8 | — | 6.4% | May 13, 2018 |
41Plan | CVE-2018-19989No exploit | In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DId-link · dir-822 firmware · CWE-78 | Critical9.8 | — | 5.5% | May 13, 2019 |
41Plan | CVE-2018-19990No exploit | In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devicd-link · dir-822 firmware · CWE-78 | Critical9.8 | — | 5.3% | May 13, 2019 |
41Plan | CVE-2018-10996No exploit | The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of serd-link · dir-629-b firmware · CWE-119 | Critical9.8 | — | 5.1% | May 12, 2018 |
41Plan | CVE-2017-9542No exploit | D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi.d-link · dir-615 firmware · CWE-287 | Critical9.8 | — | 5.1% | Jun 11, 2017 |
41Plan | CVE-2009-3347No exploit | Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrd-link · dir-400 · CWE-119 | Critical10.0 | — | 4.2% | Sep 24, 2009 |
- CVE-2018-1930061This week
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version
CriticalCVSS 9.8No exploitEPSS 74%d-link · dap-1530 firmwareApr 11, 2019
- CVE-2017-319158Plan
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.
CriticalCVSS 9.8No exploitEPSS 63%d-link · dir-130 firmwareDec 15, 2017
- CVE-2007-143553Plan
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request
CriticalCVSS 10.0WeaponizedEPSS 43%d-link · tftp serverMar 13, 2007
- CVE-2018-1998651Plan
In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B
CriticalCVSS 9.8No exploitEPSS 42%d-link · dir-818lw firmwareMay 13, 2019
- CVE-2021-2670951Plan
D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to
CriticalCVSS 9.8No exploitEPSS 40%d-link · dsl-320b-d1Apr 7, 2021
- CVE-2017-319251Plan
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.
CriticalCVSS 9.8No exploitEPSS 39%d-link · dir-130 firmwareDec 15, 2017
- CVE-2018-537148Plan
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticat
HighCVSS 8.8No exploitEPSS 42%d-link · dsl-2540u firmwareJan 12, 2018
- CVE-2014-785945Plan
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-32
CriticalCVSS 9.8No exploitEPSS 21%d-link · dns-322l firmwareAug 25, 2017
- CVE-2015-724544Plan
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read
HighCVSS 7.5Proof of conceptEPSS 45%d-link · dvg-n5402sp firmwareApr 24, 2017
- CVE-2014-785744Plan
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05
CriticalCVSS 9.8No exploitEPSS 15%d-link · dns-322l firmwareAug 25, 2017
- CVE-2014-785844Plan
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the u
CriticalCVSS 9.8No exploitEPSS 15%d-link · dnr-326 firmwareAug 25, 2017
- CVE-2015-724643Plan
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw
CriticalCVSS 9.8Proof of conceptEPSS 14%d-link · dvg-n5402sp firmwareApr 24, 2017
- CVE-2018-1998743Plan
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA,
CriticalCVSS 9.8Proof of conceptEPSS 13%d-link · dir-818lw firmwareMay 13, 2019
- CVE-2019-729743Plan
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03.
CriticalCVSS 9.8No exploitEPSS 12%d-link · dir-823g firmwareJan 31, 2019
- CVE-2016-568143Plan
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR
CriticalCVSS 9.8No exploitEPSS 12%d-link · dir-880l firmwareAug 25, 2016
- CVE-2015-724742Plan
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes
CriticalCVSS 9.8Proof of conceptEPSS 10%d-link · dvg-n5402sp firmwareApr 24, 2017
- CVE-2006-605542Plan
Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code
CriticalCVSS 10.0Proof of conceptEPSS 6%d-link · dwl-g132Nov 21, 2006
- CVE-2018-1998841Plan
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-
CriticalCVSS 9.8No exploitEPSS 7%d-link · dir-868l firmwareMay 13, 2019
- CVE-2018-2005641Plan
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices.
CriticalCVSS 9.8No exploitEPSS 7%d-link · dir-619l firmwareDec 11, 2018
- CVE-2018-1101341Plan
Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows u
CriticalCVSS 9.8No exploitEPSS 6%d-link · dir-816 a2 firmwareMay 13, 2018
- CVE-2018-1998941Plan
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DI
CriticalCVSS 9.8No exploitEPSS 6%d-link · dir-822 firmwareMay 13, 2019
- CVE-2018-1999041Plan
In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devic
CriticalCVSS 9.8No exploitEPSS 5%d-link · dir-822 firmwareMay 13, 2019
- CVE-2018-1099641Plan
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of ser
CriticalCVSS 9.8No exploitEPSS 5%d-link · dir-629-b firmwareMay 12, 2018
- CVE-2017-954241Plan
D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi.
CriticalCVSS 9.8No exploitEPSS 5%d-link · dir-615 firmwareJun 11, 2017
- CVE-2009-334741Plan
Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstr
CriticalCVSS 10.0No exploitEPSS 4%d-link · dir-400Sep 24, 2009