Vulnerabilities > Dlink > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-11 | CVE-2023-51984 | OS Command Injection vulnerability in Dlink Dir-822 Firmware 1.0.2 D-Link DIR-822+ V1.0.2 was found to contain a command injection in SetStaticRouteSettings function. | 9.8 |
2024-01-11 | CVE-2023-51987 | Missing Authentication for Critical Function vulnerability in Dlink Dir-822 Firmware 1.0.2 D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords. | 9.8 |
2024-01-11 | CVE-2023-51989 | Missing Authentication for Critical Function vulnerability in Dlink Dir-822 Firmware 1.0.2 D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to log in to administrator accounts with empty passwords. | 9.8 |
2024-01-10 | CVE-2023-51123 | Unspecified vulnerability in Dlink Dir-815 Firmware 1.01Ssb08.Bin An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component. | 9.8 |
2023-12-28 | CVE-2023-7163 | Unspecified vulnerability in Dlink D-View 8 2.0.2.89 A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. | 9.8 |
2023-12-19 | CVE-2023-49004 | Code Injection vulnerability in Dlink Dir-850L Firmware Fw223Wwb01 An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code via a crafted script to the en parameter. | 9.8 |
2023-12-07 | CVE-2023-6581 | Unspecified vulnerability in Dlink Dar-7000 Firmware A vulnerability has been found in D-Link DAR-7000 up to 20231126 and classified as critical. | 9.8 |
2023-12-01 | CVE-2023-48842 | Command Injection vulnerability in Dlink Go-Rt-Ac750 Firmware 101B03 D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi. | 9.8 |
2023-10-26 | CVE-2023-42406 | SQL Injection vulnerability in Dlink Dar-7000 Firmware 31R02B1413C SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component. | 9.8 |
2023-10-17 | CVE-2023-44693 | SQL Injection vulnerability in Dlink Dar-7000 Firmware V31R02B1413C D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php. | 9.8 |