Vulnerabilities > Dlink > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-10 | CVE-2022-29328 | Out-of-bounds Write vulnerability in Dlink Dap-1330 Firmware 1.00.B21 D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade. | 9.8 |
2022-05-10 | CVE-2022-29329 | Out-of-bounds Write vulnerability in Dlink Dap-1330 Firmware 1.00.B21 D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings. | 9.8 |
2022-05-02 | CVE-2022-28573 | OS Command Injection vulnerability in Dlink Dir-823 PRO Firmware 1.0.2 D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. | 9.8 |
2022-05-02 | CVE-2022-28571 | OS Command Injection vulnerability in Dlink Dir-882 Firmware 1.30B06 D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. | 9.8 |
2022-04-27 | CVE-2021-46442 | Unspecified vulnerability in Dlink Dir-825 Firmware In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization. | 9.8 |
2022-04-07 | CVE-2021-43474 | Command Injection vulnerability in Dlink Dir-823G Firmware 1.02B05 An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function | 9.8 |
2022-03-31 | CVE-2021-43722 | Out-of-bounds Write vulnerability in Dlink Dir-645 Firmware 1.03 D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. | 9.8 |
2022-03-28 | CVE-2022-26258 | OS Command Injection vulnerability in Dlink Dir-820L Firmware 1.05 D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. | 9.8 |
2022-03-27 | CVE-2021-44127 | Unspecified vulnerability in Dlink Dap-1360F1 Firmware 6.10 In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized. | 9.8 |
2022-03-24 | CVE-2021-31326 | Improper Authentication vulnerability in Dlink Dir-816 Firmware 1.10Cnb05 D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi. | 9.8 |