Vulnerabilities > Dlink

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-45579 Out-of-bounds Write vulnerability in Dlink products
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip/type parameter of the jingx.asp function.
network
low complexity
dlink CWE-787
critical
9.8
2023-10-16 CVE-2023-45580 Out-of-bounds Write vulnerability in Dlink products
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wild/mx and other parameters of the ddns.asp function
network
low complexity
dlink CWE-787
critical
9.8
2023-10-16 CVE-2023-44808 Out-of-bounds Write vulnerability in Dlink Dir-820L Firmware 1.05B03
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.
network
low complexity
dlink CWE-787
critical
9.8
2023-10-16 CVE-2023-44809 Unspecified vulnerability in Dlink Dir-820L Firmware 1.05B03
D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
network
low complexity
dlink
critical
9.8
2023-10-16 CVE-2023-45572 Out-of-bounds Write vulnerability in Dlink products
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the tgfile.htm function.
network
low complexity
dlink CWE-787
critical
9.8
2023-10-16 CVE-2023-45573 Out-of-bounds Write vulnerability in Dlink products
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the n parameter of the mrclfile_del.asp function.
network
low complexity
dlink CWE-787
critical
9.8
2023-10-16 CVE-2023-45574 Out-of-bounds Write vulnerability in Dlink products
Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function.
network
low complexity
dlink CWE-787
critical
9.8
2023-10-16 CVE-2023-45575 Out-of-bounds Write vulnerability in Dlink products
Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip parameter of the ip_position.asp function.
network
low complexity
dlink CWE-787
critical
9.8
2023-10-11 CVE-2023-43960 Improper Privilege Management vulnerability in Dlink Dph-400Se Firmware 2.2.15.8
An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.
network
low complexity
dlink CWE-269
8.8
2023-10-10 CVE-2023-45208 Command Injection vulnerability in Dlink Dap-1860 Firmware 1.00/1.01B0501/1.01B94
A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID.
low complexity
dlink CWE-77
8.8