Vulnerabilities > Dlink
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-26 | CVE-2022-43001 | Out-of-bounds Write vulnerability in Dlink Dir-816 Firmware 1.10B05 D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function. | 9.8 |
2022-10-26 | CVE-2022-43002 | Out-of-bounds Write vulnerability in Dlink Dir-816 Firmware 1.10B05 D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54. | 9.8 |
2022-10-26 | CVE-2022-43003 | Out-of-bounds Write vulnerability in Dlink Dir-816 Firmware 1.10B05 D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function. | 9.8 |
2022-10-19 | CVE-2022-43184 | OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.30B08 D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi. | 9.8 |
2022-10-19 | CVE-2016-20017 | Command Injection vulnerability in Dlink Dsl-2750B Firmware D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022. | 9.8 |
2022-10-13 | CVE-2022-42156 | Command Injection vulnerability in Dlink products D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings. | 8.8 |
2022-10-13 | CVE-2022-42159 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Dlink products D-Link COVR 1200,1202,1203 v1.08 was discovered to have a predictable seed in a Pseudo-Random Number Generator. | 4.3 |
2022-10-13 | CVE-2022-42160 | Command Injection vulnerability in Dlink products D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings. | 8.8 |
2022-10-13 | CVE-2022-42161 | Command Injection vulnerability in Dlink products D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS. | 8.8 |
2022-09-08 | CVE-2022-38258 | Path Traversal vulnerability in Dlink Dir-819 Firmware 1.06 A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) or access sensitive server information via manipulation of the getpage parameter in a crafted web request. | 8.1 |