Vulnerabilities > Dlink > DIR 868L Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-08-18 CVE-2023-39665 Classic Buffer Overflow vulnerability in Dlink Dir-868L Firmware 1.12Eumulti20170316
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
network
low complexity
dlink CWE-120
critical
9.8
2023-08-18 CVE-2023-39667 Classic Buffer Overflow vulnerability in Dlink Dir-868L Firmware 1.12Eumulti20170316
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
network
low complexity
dlink CWE-120
critical
9.8
2023-08-18 CVE-2023-39668 Classic Buffer Overflow vulnerability in Dlink Dir-868L Firmware 1.12Eumulti20170316
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
network
low complexity
dlink CWE-120
critical
9.8
2023-05-02 CVE-2023-29856 Classic Buffer Overflow vulnerability in Dlink Dir-868L Firmware 1.12
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow.
network
low complexity
dlink CWE-120
critical
9.8
2021-06-04 CVE-2020-29321 Insufficiently Protected Credentials vulnerability in Dlink Dir-868L Firmware 3.01
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
network
low complexity
dlink CWE-522
5.0
2020-01-02 CVE-2019-20213 Incorrect Authorization vulnerability in Dlink products
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
network
low complexity
dlink CWE-863
7.5
2019-12-30 CVE-2019-17621 OS Command Injection vulnerability in Dlink products
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
network
low complexity
dlink CWE-78
critical
9.8
2019-10-14 CVE-2017-14948 Classic Buffer Overflow vulnerability in Dlink products
Certain D-Link products are affected by: Buffer Overflow.
network
low complexity
dlink CWE-120
7.5
2019-09-09 CVE-2019-16190 Improper Authentication vulnerability in Dlink products
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.
network
low complexity
dlink CWE-287
7.5
2019-03-25 CVE-2019-7642 Missing Authentication for Critical Function vulnerability in Dlink products
D-Link routers with the mydlink feature have some web interfaces without authentication requirements.
network
low complexity
dlink CWE-306
5.0