Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Total 1533 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-13547 1 Dlink 4 Dir-822k, Dir-822k Firmware, Dwr-m920 and 1 more 2025-12-02 9.0 HIGH 8.8 HIGH
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
CVE-2025-13549 1 Dlink 2 Dir-822k, Dir-822k Firmware 2025-12-02 9.0 HIGH 8.8 HIGH
A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVE-2025-13548 1 Dlink 4 Dir-822k, Dir-822k Firmware, Dwr-m920 and 1 more 2025-12-02 9.0 HIGH 8.8 HIGH
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13550 1 Dlink 4 Dir-822k, Dir-822k Firmware, Dwr-m920 and 1 more 2025-12-02 9.0 HIGH 8.8 HIGH
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-13551 1 Dlink 4 Dir-822k, Dir-822k Firmware, Dwr-m920 and 1 more 2025-12-02 9.0 HIGH 8.8 HIGH
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
CVE-2025-13552 1 Dlink 4 Dir-822k, Dir-822k Firmware, Dwr-m920 and 1 more 2025-12-02 9.0 HIGH 8.8 HIGH
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
CVE-2025-8155 1 Dlink 2 Dcs-6010l, Dcs-6010l Firmware 2025-12-01 4.0 MEDIUM 3.5 LOW
A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vb.htm of the component Management Application. The manipulation of the argument paratest leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2018-25120 1 Dlink 2 Dns-343, Dns-343 Firmware 2025-11-28 N/A 9.8 CRITICAL
D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulnerability in the Mail Test functionality. The web maintenance script posts to the internal goForm endpoint '/goform/Mail_Test' and uses several form parameters directly in a call to a system email utility without proper input validation. An unauthenticated remote attacker can supply crafted form data that injects shell commands, resulting in execution as root on the device. NOTE: The DNS-343 product line has been declared end-of-life.
CVE-2022-50596 1 Dlink 2 Dir-1260, Dir-1260 Firmware 2025-11-28 N/A 9.8 CRITICAL
D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw specifically exists within the SetDest/Dest/Target arguments to the GetDeviceSettings form. The management interface is accessible over HTTP and HTTPS on the local and Wi-Fi networks and optionally from the Internet.
CVE-2025-13562 1 Dlink 2 Dir-852, Dir-852 Firmware 2025-11-26 7.5 HIGH 7.3 HIGH
A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-13553 1 Dlink 2 Dwr-m920, Dwr-m920 Firmware 2025-11-26 9.0 HIGH 8.8 HIGH
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-13188 1 Dlink 2 Dir-816l, Dir-816l Firmware 2025-11-20 10.0 HIGH 9.8 CRITICAL
A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument Password results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-13189 1 Dlink 2 Dir-816l, Dir-816l Firmware 2025-11-20 9.0 HIGH 8.8 HIGH
A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-13190 1 Dlink 2 Dir-816l, Dir-816l Firmware 2025-11-20 9.0 HIGH 8.8 HIGH
A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the file /portal/__ajax_exporer.sgi. The manipulation of the argument en results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-11338 1 Dlink 2 Di-7100g C1, Di-7100g C1 Firmware 2025-11-19 9.0 HIGH 8.8 HIGH
A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the file /webchat/login.cgi of the component jhttpd. Executing manipulation of the argument openid can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2025-11335 1 Dlink 2 Di-7100g C1, Di-7100g C1 Firmware 2025-11-19 5.8 MEDIUM 4.7 MEDIUM
A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_46409C of the file /msp_info.htm?flag=qos of the component jhttpd. This manipulation of the argument iface causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-11339 1 Dlink 2 Di-7100g C1, Di-7100g C1 Firmware 2025-11-19 9.0 HIGH 8.8 HIGH
A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the file /webchat/hi_block.asp of the component jhttpd. The manipulation of the argument popupId leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-11407 1 Dlink 2 Di-7001mini-8g, Di-7001mini-8g Firmware 2025-11-19 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1. Impacted is an unknown function of the file /upgrade_filter.asp. This manipulation of the argument path causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-11408 1 Dlink 2 Di-7001mini-8g, Di-7001mini-8g Firmware 2025-11-19 9.0 HIGH 8.8 HIGH
A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-13191 1 Dlink 2 Dir-816l, Dir-816l Firmware 2025-11-19 9.0 HIGH 8.8 HIGH
A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the file /soap.cgi. This manipulation causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.