Vulnerabilities > D Link

DATE CVE VULNERABILITY TITLE RISK
2019-10-25 CVE-2013-4857 XML Injection (aka Blind XPath Injection) vulnerability in D-Link Dir-865L Firmware
D-Link DIR-865L has PHP File Inclusion in the router xml file.
network
low complexity
d-link CWE-91
7.5
2019-10-25 CVE-2013-4856 Information Exposure vulnerability in D-Link Dir-865L Firmware
D-Link DIR-865L has Information Disclosure.
2.9
2019-10-25 CVE-2013-4855 Path Traversal vulnerability in D-Link Dir-865L Firmware
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.
7.9
2019-08-27 CVE-2019-13265 Unspecified vulnerability in D-Link Dir-825/Ac G1 Firmware
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device.
low complexity
d-link
5.8
2019-08-27 CVE-2019-13264 Unspecified vulnerability in D-Link Dir-825/Ac G1 Firmware
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device.
low complexity
d-link
5.8
2019-08-27 CVE-2019-13263 Incorrect Resource Transfer Between Spheres vulnerability in D-Link Dir-825/Ac G1 Firmware
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device.
low complexity
d-link CWE-669
5.8
2019-07-02 CVE-2017-8408 Command Injection vulnerability in D-Link Dcs-1130 Firmware
An issue was discovered on D-Link DCS-1130 devices.
network
low complexity
d-link CWE-77
critical
10.0
2019-05-13 CVE-2018-19990 OS Command Injection vulnerability in D-Link Dir-822 Firmware 202Krb06
In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices.
network
low complexity
d-link CWE-78
critical
10.0
2019-05-13 CVE-2018-19989 OS Command Injection vulnerability in D-Link Dir-822 Firmware 202Krb06/3.10B06
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices.
network
low complexity
d-link CWE-78
critical
10.0
2019-05-13 CVE-2018-19988 OS Command Injection vulnerability in D-Link Dir-868L Firmware 2.05B02
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices.
network
low complexity
d-link CWE-78
7.5