Vulnerabilities > Dlink > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-02-05 | CVE-2019-7388 | Information Exposure vulnerability in Dlink Dir-823G Firmware 1.02B03 An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. | 7.5 |
2019-02-01 | CVE-2019-7298 | OS Command Injection vulnerability in Dlink Dir-823G Firmware An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. | 8.1 |
2019-01-31 | CVE-2018-15517 | Server-Side Request Forgery (SSRF) vulnerability in Dlink Central Wifimanager 1.03 The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually allows outbound TCP to any port on any IP address, leading to SSRF, as demonstrated by an index.php/System/MailConnect/host/127.0.0.1/port/22/secure/ URI. | 8.6 |
2019-01-31 | CVE-2018-15515 | Unspecified vulnerability in Dlink Central Wifimanager 1.03R0098 The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the CaptivelPortal.exe subdirectory under the D-Link directory, which allows unprivileged local users to gain SYSTEM privileges. | 7.8 |
2019-01-09 | CVE-2018-20674 | Unspecified vulnerability in Dlink products D-Link DIR-822 C1 before v3.11B01Beta, DIR-822-US C1 before v3.11B01Beta, DIR-850L A* before v1.21B08Beta, DIR-850L B* before v2.22B03Beta, and DIR-880L A* before v1.20B02Beta devices allow authenticated remote command execution. | 8.8 |
2018-12-20 | CVE-2018-18767 | Inadequate Encryption Strength vulnerability in multiple products An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. | 7.0 |
2018-12-20 | CVE-2018-18441 | Information Exposure vulnerability in multiple products D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. | 7.5 |
2018-10-17 | CVE-2018-10823 | OS Command Injection vulnerability in Dlink products An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. | 8.8 |
2018-10-17 | CVE-2018-10822 | Path Traversal vulnerability in Dlink products Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers to read arbitrary files via a /.. | 7.5 |
2018-10-08 | CVE-2018-17442 | Unrestricted Upload of File with Dangerous Type vulnerability in Dlink Central Wifimanager An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. | 8.8 |