Vulnerabilities > Dlink

DATE CVE VULNERABILITY TITLE RISK
2023-01-31 CVE-2022-47035 Classic Buffer Overflow vulnerability in Dlink Dir-825 Firmware 1.33.0.44Ebdd4Embedded
Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.
network
low complexity
dlink CWE-120
critical
9.8
2023-01-27 CVE-2022-48107 OS Command Injection vulnerability in Dlink DIR 878 Firmware 1.30B08
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress.
network
low complexity
dlink CWE-78
critical
9.8
2023-01-27 CVE-2022-48108 OS Command Injection vulnerability in Dlink DIR 878 Firmware 1.30B08
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask.
network
low complexity
dlink CWE-78
critical
9.8
2023-01-26 CVE-2022-40717 Out-of-bounds Write vulnerability in Dlink Dir-2150 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected D-Link DIR-2150 4.0.1 routers.
low complexity
dlink CWE-787
8.8
2023-01-26 CVE-2022-40718 Out-of-bounds Write vulnerability in Dlink Dir-2150 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected D-Link DIR-2150 4.0.1 routers.
low complexity
dlink CWE-787
8.8
2023-01-26 CVE-2022-40719 OS Command Injection vulnerability in Dlink Dir-2150 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers.
low complexity
dlink CWE-78
8.8
2023-01-26 CVE-2022-40720 OS Command Injection vulnerability in Dlink Dir-2150 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers.
low complexity
dlink CWE-78
8.8
2023-01-26 CVE-2022-41140 Out-of-bounds Write vulnerability in Dlink products
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers.
low complexity
dlink CWE-787
8.8
2023-01-19 CVE-2022-46476 OS Command Injection vulnerability in Dlink Dir-859 A1 Firmware 1.05
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
network
low complexity
dlink CWE-78
critical
9.8
2023-01-17 CVE-2022-46475 Out-of-bounds Write vulnerability in Dlink Dir-645 Firmware 1.06B01Beta01
D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function.
network
low complexity
dlink CWE-787
critical
9.8