Записи dlink
1 777 опубликованных записей вендора dlink.
Профиль для исследователя
- Попали в KEV
- 28 · 1,6 %
- С эксплойтом
- 45 · 2,5 %
- Pre-auth RCE
- 425
- С записью об исправлении
- 0,2 %
- Медиана: публикация → KEV
- 954 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')250
- CWE-121 Stack-based Buffer Overflow204
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer193
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')174
- CWE-787 Out-of-bounds Write149
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')127
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 777 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2024-3273Готовый эксплойт | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injectiondlink · dns-320l firmware · CWE-77 | Критическая9,8 | KEV | 100,0 % | 3 апр. 2024 г. |
99Срочно | CVE-2019-16920Готовый эксплойт | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.dlink · dir-655 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 27 сент. 2019 г. |
99Срочно | CVE-2014-8361Готовый эксплойт | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploirealtek · realtek sdk | Критическая9,8 | KEV | 100,0 % | 1 мая 2015 г. |
99Срочно | CVE-2020-25506Готовый эксплойт | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary dlink · dns-320 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 2 февр. 2021 г. |
98Срочно | CVE-2024-3272Готовый эксплойт | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentialsdlink · dns-320l firmware · CWE-798 | Критическая9,8 | KEV | 98,0 % | 3 апр. 2024 г. |
98Срочно | CVE-2023-25280Готовый эксплойт | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with tdlink · dir-820l firmware · CWE-78 | Критическая9,8 | KEV | 97,9 % | 15 мар. 2023 г. |
98Срочно | CVE-2021-45382Готовый эксплойт | A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-dlink · dir-820l firmware · CWE-78 | Критическая9,8 | KEV | 97,8 % | 17 февр. 2022 г. |
98Срочно | CVE-2018-6530Готовый эксплойт | OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previousdlink · dir-860l firmware · CWE-78 | Критическая9,8 | KEV | 96,7 % | 6 мар. 2018 г. |
97Срочно | CVE-2022-26258Готовый эксплойт | D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.dlink · dir-820l firmware · CWE-78 | Критическая9,8 | KEV | 92,0 % | 27 мар. 2022 г. |
96Срочно | CVE-2019-17621Готовый эксплойт | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execdlink · dir-859 firmware · CWE-78 | Критическая9,8 | KEV | 89,6 % | 30 дек. 2019 г. |
95Срочно | CVE-2019-16057Готовый эксплойт | The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.dlink · dns-320 firmware · CWE-78 | Критическая9,8 | KEV | 86,5 % | 16 сент. 2019 г. |
94Срочно | CVE-2015-2051Готовый эксплойт | The D-Link DIR-645 Wired/Wireless Router Rev.dlink · dir-645 firmware · CWE-77 | Высокая8,8 | KEV | 97,1 % | 23 февр. 2015 г. |
94Срочно | CVE-2015-1187Готовый эксплойт | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ctrendnet · tew-731br firmware · CWE-287 | Критическая9,8 | KEV | 82,9 % | 21 сент. 2017 г. |
94Срочно | CVE-2024-0769Готовый эксплойт | D-Link DIR-859 HTTP POST Request hedwig.cgi path traversaldlink · dir-859 firmware · CWE-22 | Критическая9,8 | KEV | 82,7 % | 21 янв. 2024 г. |
90Срочно | CVE-2019-20500Готовый эксплойт | D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality idlink · dwl-2600ap firmware · CWE-78 | Высокая7,8 | KEV | 97,1 % | 5 мар. 2020 г. |
89Срочно | CVE-2020-25078Готовый эксплойт | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.dlink · dcs-4603 firmware | Высокая7,5 | KEV | 97,5 % | 2 сент. 2020 г. |
88Срочно | CVE-2016-20017Готовый эксплойт | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wildlink · dsl-2750b firmware · CWE-77 | Критическая9,8 | KEV | 64,2 % | 19 окт. 2022 г. |
86Срочно | CVE-2021-40655Готовый эксплойт | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.dlink · dir-605l firmware · CWE-863 | Высокая7,5 | KEV | 86,7 % | 24 сент. 2021 г. |
86Срочно | CVE-2022-37055Готовый эксплойт | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,dlink · go-rt-ac750 firmware · CWE-120 | Критическая9,8 | KEV | 55,5 % | 28 авг. 2022 г. |
85Срочно | CVE-2020-29557Готовый эксплойт | An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.dlink · dir-825 r1 firmware · CWE-119 | Критическая9,8 | KEV | 54,3 % | 29 янв. 2021 г. |
84Срочно | CVE-2025-29635Готовый эксплойт | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remotedlink · dir-823x firmware · CWE-77 | Высокая7,2 | KEV | 87,9 % | 25 мар. 2025 г. |
81Срочно | CVE-2020-25079Готовый эксплойт | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.dlink · dcs-4703e firmware · CWE-77 | Высокая8,8 | KEV | 54,0 % | 2 сент. 2020 г. |
79На этой неделе | CVE-2016-11021Готовый эксплойт | setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand paradlink · dcs-930l firmware · CWE-78 | Высокая7,2 | KEV | 68,9 % | 8 мар. 2020 г. |
75На этой неделе | CVE-2014-100005Готовый эксплойт | Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.dlink · dir-600 firmware · CWE-352 | Высокая8,0 | KEV | 43,5 % | 13 янв. 2015 г. |
75На этой неделе | CVE-2022-40799Готовый эксплойт | Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on thedlink · dnr-322l firmware · CWE-494 | Высокая8,8 | KEV | 33,7 % | 29 нояб. 2022 г. |
- CVE-2024-327399Срочно
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dns-320l firmware3 апр. 2024 г.
- CVE-2019-1692099Срочно
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dir-655 firmware27 сент. 2019 г.
- CVE-2014-836199Срочно
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %realtek · realtek sdk1 мая 2015 г.
- CVE-2020-2550699Срочно
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dns-320 firmware2 февр. 2021 г.
- CVE-2024-327298Срочно
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %dlink · dns-320l firmware3 апр. 2024 г.
- CVE-2023-2528098Срочно
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with t
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %dlink · dir-820l firmware15 мар. 2023 г.
- CVE-2021-4538298Срочно
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %dlink · dir-820l firmware17 февр. 2022 г.
- CVE-2018-653098Срочно
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %dlink · dir-860l firmware6 мар. 2018 г.
- CVE-2022-2625897Срочно
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %dlink · dir-820l firmware27 мар. 2022 г.
- CVE-2019-1762196Срочно
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to exec
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %dlink · dir-859 firmware30 дек. 2019 г.
- CVE-2019-1605795Срочно
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %dlink · dns-320 firmware16 сент. 2019 г.
- CVE-2015-205194Срочно
The D-Link DIR-645 Wired/Wireless Router Rev.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 97 %dlink · dir-645 firmware23 февр. 2015 г.
- CVE-2015-118794Срочно
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %trendnet · tew-731br firmware21 сент. 2017 г.
- CVE-2024-076994Срочно
D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %dlink · dir-859 firmware21 янв. 2024 г.
- CVE-2019-2050090Срочно
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality i
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 97 %dlink · dwl-2600ap firmware5 мар. 2020 г.
- CVE-2020-2507889Срочно
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 98 %dlink · dcs-4603 firmware2 сент. 2020 г.
- CVE-2016-2001788Срочно
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %dlink · dsl-2750b firmware19 окт. 2022 г.
- CVE-2021-4065586Срочно
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %dlink · dir-605l firmware24 сент. 2021 г.
- CVE-2022-3705586Срочно
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 56 %dlink · go-rt-ac750 firmware28 авг. 2022 г.
- CVE-2020-2955785Срочно
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 54 %dlink · dir-825 r1 firmware29 янв. 2021 г.
- CVE-2025-2963584Срочно
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 88 %dlink · dir-823x firmware25 мар. 2025 г.
- CVE-2020-2507981Срочно
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 54 %dlink · dcs-4703e firmware2 сент. 2020 г.
- CVE-2016-1102179На этой неделе
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand para
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 69 %dlink · dcs-930l firmware8 мар. 2020 г.
- CVE-2014-10000575На этой неделе
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev.
ВысокаяCVSS 8,0KEVГотовый эксплойтEPSS 43 %dlink · dir-600 firmware13 янв. 2015 г.
- CVE-2022-4079975На этой неделе
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 34 %dlink · dnr-322l firmware29 нояб. 2022 г.