Vulnerabilities > Dlink > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-31 CVE-2018-15515 Unspecified vulnerability in Dlink Central Wifimanager 1.03R0098
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges.
local
low complexity
dlink
7.8
2019-01-09 CVE-2018-20674 Unspecified vulnerability in Dlink products
D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authenticated remote command execution.
network
low complexity
dlink
8.8
2018-12-20 CVE-2018-18767 Inadequate Encryption Strength vulnerability in multiple products
An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06.
local
high complexity
dlink d-link CWE-326
7.0
2018-12-20 CVE-2018-18441 Information Exposure vulnerability in multiple products
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration.
network
low complexity
d-link dlink CWE-200
7.5
2018-10-17 CVE-2018-10823 OS Command Injection vulnerability in Dlink products
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices.
network
low complexity
dlink CWE-78
8.8
2018-10-17 CVE-2018-10822 Path Traversal vulnerability in Dlink products
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers to read arbitrary files via a /..
network
low complexity
dlink CWE-22
7.5
2018-10-08 CVE-2018-17442 Unrestricted Upload of File with Dangerous Type vulnerability in Dlink Central Wifimanager
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1.
network
low complexity
dlink CWE-434
8.8
2018-08-29 CVE-2018-12710 Cleartext Transmission of Sensitive Information vulnerability in Dlink Dir-601 Firmware 2.02Na
An issue was discovered on D-Link DIR-601 2.02NA devices.
low complexity
dlink CWE-319
8.0
2018-08-24 CVE-2017-11564 Out-of-bounds Write vulnerability in Dlink Eyeon Baby Monitor Firmware 1.08.1
The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework.
network
low complexity
dlink CWE-787
8.8
2018-05-10 CVE-2018-10957 Cross-Site Request Forgery (CSRF) vulnerability in Dlink Dir-868L Firmware 1.12
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password.
network
low complexity
dlink CWE-352
8.8