Vulnerabilities > Dlink > DIR 868L Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2020-29321 Insufficiently Protected Credentials vulnerability in Dlink Dir-868L Firmware 3.01
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
network
low complexity
dlink CWE-522
7.5
2020-01-02 CVE-2019-20213 Incorrect Authorization vulnerability in Dlink products
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
network
low complexity
dlink CWE-863
7.5
2019-03-25 CVE-2019-7642 Missing Authentication for Critical Function vulnerability in Dlink products
D-Link routers with the mydlink feature have some web interfaces without authentication requirements.
network
low complexity
dlink CWE-306
7.5
2018-05-10 CVE-2018-10957 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dir-868L Firmware 1.12
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password.
network
low complexity
dlink CWE-352
8.8