Vulnerabilities > Dlink > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-29 CVE-2022-43632 Unspecified vulnerability in Dlink Dir-1935 Firmware 1.03
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
low complexity
dlink
6.8
2023-03-29 CVE-2022-43633 OS Command Injection vulnerability in Dlink Dir-1935 Firmware 1.03
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers.
low complexity
dlink CWE-78
6.8
2023-03-15 CVE-2023-25282 Out-of-bounds Write vulnerability in Dlink Dir-820L Firmware 1.06
A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.log_to_syslog and log_opt_dropPackets parameters to mydlink_api.ccp.
network
low complexity
dlink CWE-787
6.5
2022-10-13 CVE-2022-42159 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Dlink products
D-Link COVR 1200,1202,1203 v1.08 was discovered to have a predictable seed in a Pseudo-Random Number Generator.
network
low complexity
dlink CWE-335
4.3
2022-08-23 CVE-2022-35191 Improper Resource Shutdown or Release vulnerability in Dlink Dsl-3782 Firmware 1.01
D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.
network
low complexity
dlink CWE-404
6.5
2022-05-17 CVE-2022-29332 Path Traversal vulnerability in Dlink Dir-825 Firmware 2022.01.1313.48
D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal.
network
low complexity
dlink CWE-22
6.5
2022-03-04 CVE-2021-46353 Information Exposure Through an Error Message vulnerability in Dlink Dir-X1860 Firmware 1.03
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.
network
low complexity
dlink CWE-209
5.3
2022-03-04 CVE-2022-25106 Out-of-bounds Write vulnerability in Dlink Dir-859 A3 Firmware and Dir-859 Firmware
D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main.
local
low complexity
dlink CWE-787
5.5
2022-03-04 CVE-2021-46379 Open Redirect vulnerability in Dlink Dir-850L Firmware 1.08Trb03
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
network
low complexity
dlink CWE-601
6.1
2022-02-18 CVE-2021-46108 Cross-site Scripting vulnerability in Dlink Dsl-2730E Firmware Ct20131125
D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance configuration.
network
low complexity
dlink CWE-79
5.4