Записи D-Link
115 опубликованных записей вендора d-link.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,9 %
- Pre-auth RCE
- 22
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')14
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer12
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-287 Improper Authentication7
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
115 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2018-19300Эксплойта нет | On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware versiond-link · dap-1530 firmware · CWE-20 | Критическая9,8 | — | 74,3 % | 11 апр. 2019 г. |
58В плане | CVE-2017-3191Эксплойта нет | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.d-link · dir-130 firmware · CWE-294 | Критическая9,8 | — | 62,5 % | 15 дек. 2017 г. |
53В плане | CVE-2007-1435Готовый эксплойт | Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT requestd-link · tftp server | Критическая10,0 | — | 42,8 % | 13 мар. 2007 г. |
51В плане | CVE-2018-19986Эксплойта нет | In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.Bd-link · dir-818lw firmware · CWE-78 | Критическая9,8 | — | 41,6 % | 13 мая 2019 г. |
51В плане | CVE-2021-26709Эксплойта нет | D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers tod-link · dsl-320b-d1 · CWE-787 | Критическая9,8 | — | 40,1 % | 7 апр. 2021 г. |
51В плане | CVE-2017-3192Эксплойта нет | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.d-link · dir-130 firmware · CWE-522 | Критическая9,8 | — | 39,5 % | 15 дек. 2017 г. |
48В плане | CVE-2018-5371Эксплойта нет | diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticatd-link · dsl-2540u firmware · CWE-78 | Высокая8,8 | — | 42,0 % | 12 янв. 2018 г. |
45В плане | CVE-2014-7859Эксплойта нет | Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-32d-link · dns-322l firmware · CWE-119 | Критическая9,8 | — | 20,9 % | 25 авг. 2017 г. |
44В плане | CVE-2015-7245Proof of concept | Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read d-link · dvg-n5402sp firmware · CWE-22 | Высокая7,5 | — | 45,5 % | 24 апр. 2017 г. |
44В плане | CVE-2014-7857Эксплойта нет | D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05d-link · dns-322l firmware · CWE-287 | Критическая9,8 | — | 15,2 % | 25 авг. 2017 г. |
44В плане | CVE-2014-7858Эксплойта нет | The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the ud-link · dnr-326 firmware · CWE-287 | Критическая9,8 | — | 15,2 % | 25 авг. 2017 г. |
43В плане | CVE-2015-7246Proof of concept | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the twd-link · dvg-n5402sp firmware · CWE-798 | Критическая9,8 | — | 14,3 % | 24 апр. 2017 г. |
43В плане | CVE-2018-19987Proof of concept | D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, d-link · dir-818lw firmware · CWE-78 | Критическая9,8 | — | 12,9 % | 13 мая 2019 г. |
43В плане | CVE-2019-7297Эксплойта нет | An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03.d-link · dir-823g firmware · CWE-78 | Критическая9,8 | — | 12,5 % | 31 янв. 2019 г. |
43В плане | CVE-2016-5681Эксплойта нет | Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIRd-link · dir-880l firmware · CWE-119 | Критическая9,8 | — | 11,9 % | 25 авг. 2016 г. |
42В плане | CVE-2015-7247Proof of concept | D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes d-link · dvg-n5402sp firmware · CWE-200 | Критическая9,8 | — | 10,2 % | 24 апр. 2017 г. |
42В плане | CVE-2006-6055Proof of concept | Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary coded-link · dwl-g132 | Критическая10,0 | — | 5,9 % | 21 нояб. 2006 г. |
41В плане | CVE-2018-19988Эксплойта нет | In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-d-link · dir-868l firmware · CWE-78 | Критическая9,8 | — | 7,4 % | 13 мая 2019 г. |
41В плане | CVE-2018-20056Эксплойта нет | An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices.d-link · dir-619l firmware · CWE-787 | Критическая9,8 | — | 7,0 % | 11 дек. 2018 г. |
41В плане | CVE-2018-11013Эксплойта нет | Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows ud-link · dir-816 a2 firmware · CWE-787 | Критическая9,8 | — | 6,4 % | 13 мая 2018 г. |
41В плане | CVE-2018-19989Эксплойта нет | In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DId-link · dir-822 firmware · CWE-78 | Критическая9,8 | — | 5,5 % | 13 мая 2019 г. |
41В плане | CVE-2018-19990Эксплойта нет | In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devicd-link · dir-822 firmware · CWE-78 | Критическая9,8 | — | 5,3 % | 13 мая 2019 г. |
41В плане | CVE-2018-10996Эксплойта нет | The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of serd-link · dir-629-b firmware · CWE-119 | Критическая9,8 | — | 5,1 % | 12 мая 2018 г. |
41В плане | CVE-2017-9542Эксплойта нет | D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi.d-link · dir-615 firmware · CWE-287 | Критическая9,8 | — | 5,1 % | 11 июн. 2017 г. |
41В плане | CVE-2009-3347Эксплойта нет | Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrd-link · dir-400 · CWE-119 | Критическая10,0 | — | 4,2 % | 24 сент. 2009 г. |
- CVE-2018-1930061На этой неделе
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version
КритическаяCVSS 9,8Эксплойта нетEPSS 74 %d-link · dap-1530 firmware11 апр. 2019 г.
- CVE-2017-319158В плане
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.
КритическаяCVSS 9,8Эксплойта нетEPSS 63 %d-link · dir-130 firmware15 дек. 2017 г.
- CVE-2007-143553В плане
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request
КритическаяCVSS 10,0Готовый эксплойтEPSS 43 %d-link · tftp server13 мар. 2007 г.
- CVE-2018-1998651В плане
In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B
КритическаяCVSS 9,8Эксплойта нетEPSS 42 %d-link · dir-818lw firmware13 мая 2019 г.
- CVE-2021-2670951В плане
D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to
КритическаяCVSS 9,8Эксплойта нетEPSS 40 %d-link · dsl-320b-d17 апр. 2021 г.
- CVE-2017-319251В плане
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials.
КритическаяCVSS 9,8Эксплойта нетEPSS 39 %d-link · dir-130 firmware15 дек. 2017 г.
- CVE-2018-537148В плане
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticat
ВысокаяCVSS 8,8Эксплойта нетEPSS 42 %d-link · dsl-2540u firmware12 янв. 2018 г.
- CVE-2014-785945В плане
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-32
КритическаяCVSS 9,8Эксплойта нетEPSS 21 %d-link · dns-322l firmware25 авг. 2017 г.
- CVE-2015-724544В плане
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read
ВысокаяCVSS 7,5Proof of conceptEPSS 45 %d-link · dvg-n5402sp firmware24 апр. 2017 г.
- CVE-2014-785744В плане
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %d-link · dns-322l firmware25 авг. 2017 г.
- CVE-2014-785844В плане
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the u
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %d-link · dnr-326 firmware25 авг. 2017 г.
- CVE-2015-724643В плане
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw
КритическаяCVSS 9,8Proof of conceptEPSS 14 %d-link · dvg-n5402sp firmware24 апр. 2017 г.
- CVE-2018-1998743В плане
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA,
КритическаяCVSS 9,8Proof of conceptEPSS 13 %d-link · dir-818lw firmware13 мая 2019 г.
- CVE-2019-729743В плане
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03.
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %d-link · dir-823g firmware31 янв. 2019 г.
- CVE-2016-568143В плане
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %d-link · dir-880l firmware25 авг. 2016 г.
- CVE-2015-724742В плане
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes
КритическаяCVSS 9,8Proof of conceptEPSS 10 %d-link · dvg-n5402sp firmware24 апр. 2017 г.
- CVE-2006-605542В плане
Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132 wireless adapter allows remote attackers to execute arbitrary code
КритическаяCVSS 10,0Proof of conceptEPSS 6 %d-link · dwl-g13221 нояб. 2006 г.
- CVE-2018-1998841В плане
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %d-link · dir-868l firmware13 мая 2019 г.
- CVE-2018-2005641В плане
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %d-link · dir-619l firmware11 дек. 2018 г.
- CVE-2018-1101341В плане
Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows u
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %d-link · dir-816 a2 firmware13 мая 2018 г.
- CVE-2018-1998941В плане
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DI
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %d-link · dir-822 firmware13 мая 2019 г.
- CVE-2018-1999041В плане
In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devic
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %d-link · dir-822 firmware13 мая 2019 г.
- CVE-2018-1099641В плане
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of ser
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %d-link · dir-629-b firmware12 мая 2018 г.
- CVE-2017-954241В плане
D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %d-link · dir-615 firmware11 июн. 2017 г.
- CVE-2009-334741В плане
Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstr
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %d-link · dir-40024 сент. 2009 г.