PRIOn Logo

Search KB


Search our pre-analyzed vulnerability database

Total Results: 762

of 39

Published:   Updated:

Vulnerability Type: Command injection

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.

Published:   Updated:

Vulnerability Type: Improper access control

Vendor(s):  Dlink
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v36.8

** UNSUPPORTED WHEN ASSIGNED ** D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php.

Published:   Updated:

Vulnerability Type: Sql injection

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wild/mx and other parameters of the ddns.asp function

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip/type parameter of the jingx.asp function.

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the pap_en/chap_en parameter of the pppoe_base.asp function.

Published:   Updated:

Vulnerability Type: Stack overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wanid parameter of the H5/speedlimit.data function.

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the remove_ext_proto/remove_ext_port parameter of the upnp_ctrl.asp function.

Published:   Updated:

Vulnerability Type: Stack overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip parameter of the ip_position.asp function.

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the n parameter of the mrclfile_del.asp function.

Published:   Updated:

Vulnerability Type: Buffer overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the tgfile.htm function.

Published:   Updated:

Vulnerability Type: Design/Logic Flaw

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.

Published:   Updated:

Vulnerability Type: Stack overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.

Published:   Updated:

Vulnerability Type: Design/Logic Flaw

Vendor(s):  Dlink
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v38.8

An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.

Published:   Updated:

Vulnerability Type: Command injection

Vendor(s):  Dlink
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v38.8

A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID. Also, network names containing single quotes (in the range of the repeater) can result in a denial of service.

Published:   Updated:

Vulnerability Type: Code injection

Vendor(s):  Dlink
Routine
Remediate Within 6 Months
CVSS v2N/ACVSS v38.8

An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.

Published:   Updated:

Vulnerability Type: Stack overflow

Vendor(s):  Dlink
Significant
Remediate Within one Month
CVSS v2N/ACVSS v39.8

D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

of 39