Vulnerabilities > Dlink > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-28 | CVE-2023-7163 | Unspecified vulnerability in Dlink D-View 8 2.0.2.89 A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. | 9.8 |
2023-12-19 | CVE-2023-49004 | Code Injection vulnerability in Dlink Dir-850L Firmware Fw223Wwb01 An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter. | 9.8 |
2023-12-07 | CVE-2023-6581 | Unspecified vulnerability in Dlink Dar-7000 Firmware A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. | 9.8 |
2023-12-01 | CVE-2023-48842 | Command Injection vulnerability in Dlink Go-Rt-Ac750 Firmware 101B03 D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi. | 9.8 |
2023-10-26 | CVE-2023-42406 | SQL Injection vulnerability in Dlink Dar-7000 Firmware 31R02B1413C SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component. | 9.8 |
2023-10-17 | CVE-2023-44693 | SQL Injection vulnerability in Dlink Dar-7000 Firmware V31R02B1413C D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. | 9.8 |
2023-10-17 | CVE-2023-44694 | SQL Injection vulnerability in Dlink Dar-7000 Firmware V31R02B1413C D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php. | 9.8 |
2023-10-16 | CVE-2023-45576 | Out-of-bounds Write vulnerability in Dlink products Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the remove_ext_proto/remove_ext_port parameter of the upnp_ctrl.asp function. | 9.8 |
2023-10-16 | CVE-2023-45577 | Out-of-bounds Write vulnerability in Dlink products Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wanid parameter of the H5/speedlimit.data function. | 9.8 |
2023-10-16 | CVE-2023-45578 | Out-of-bounds Write vulnerability in Dlink products Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the pap_en/chap_en parameter of the pppoe_base.asp function. | 9.8 |