Skip to content
Noroxi

dlink records

1,777 published records for vendor dlink.

All records

1,777 records
  • D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dlink · dns-320l firmwareApr 3, 2024

  • Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dlink · dir-655 firmwareSep 27, 2019

  • The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploi

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    realtek · realtek sdkMay 1, 2015

  • D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dlink · dns-320 firmwareFeb 2, 2021

  • D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    dlink · dns-320l firmwareApr 3, 2024

  • OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with t

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    dlink · dir-820l firmwareMar 15, 2023

  • A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    dlink · dir-820l firmwareFeb 17, 2022

  • OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    dlink · dir-860l firmwareMar 6, 2018

  • D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    dlink · dir-820l firmwareMar 27, 2022

  • The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to exec

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    dlink · dir-859 firmwareDec 30, 2019

  • The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    dlink · dns-320 firmwareSep 16, 2019

  • The D-Link DIR-645 Wired/Wireless Router Rev.

    HighCVSS 8.8KEVWeaponizedEPSS 97%

    dlink · dir-645 firmwareFeb 23, 2015

  • The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.c

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    trendnet · tew-731br firmwareSep 21, 2017

  • D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal

    CriticalCVSS 9.8KEVWeaponizedEPSS 83%

    dlink · dir-859 firmwareJan 21, 2024

  • D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality i

    HighCVSS 7.8KEVWeaponizedEPSS 97%

    dlink · dwl-2600ap firmwareMar 5, 2020

  • An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.

    HighCVSS 7.5KEVWeaponizedEPSS 98%

    dlink · dcs-4603 firmwareSep 2, 2020

  • D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil

    CriticalCVSS 9.8KEVWeaponizedEPSS 64%

    dlink · dsl-2750b firmwareOct 19, 2022

  • An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.

    HighCVSS 7.5KEVWeaponizedEPSS 87%

    dlink · dir-605l firmwareSep 24, 2021

  • D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

    CriticalCVSS 9.8KEVWeaponizedEPSS 56%

    dlink · go-rt-ac750 firmwareAug 28, 2022

  • An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.

    CriticalCVSS 9.8KEVWeaponizedEPSS 54%

    dlink · dir-825 r1 firmwareJan 29, 2021

  • A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote

    HighCVSS 7.2KEVWeaponizedEPSS 88%

    dlink · dir-823x firmwareMar 25, 2025

  • An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.

    HighCVSS 8.8KEVWeaponizedEPSS 54%

    dlink · dcs-4703e firmwareSep 2, 2020

  • CVE-2016-11021
    79This week

    setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand para

    HighCVSS 7.2KEVWeaponizedEPSS 69%

    dlink · dcs-930l firmwareMar 8, 2020

  • CVE-2014-100005
    75This week

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.

    HighCVSS 8.0KEVWeaponizedEPSS 43%

    dlink · dir-600 firmwareJan 13, 2015

  • CVE-2022-40799
    75This week

    Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the

    HighCVSS 8.8KEVWeaponizedEPSS 34%

    dlink · dnr-322l firmwareNov 29, 2022