Skip to main content

Vendor/product archive

dlink / dir-615 CVEs

Beta · best-effort

27 CVEs tagged to dlink / dir-61510 Critical, 11 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-2152

Published Feb 8, 2026

A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a ma…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-2151

Published Feb 8, 2026

A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argume…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1506

Published Jan 28, 2026

A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1505

Published Jan 28, 2026

A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-1448

Published Jan 27, 2026

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Perfor…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2018-25115

Published Aug 27, 2025

Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi e…

CVSS 10.0 · Critical

CVE-2021-40654

Published Sep 24, 2021

An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37388

Published Aug 6, 2021

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote cod…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17353

Published Oct 9, 2019

An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of infor…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16920

Published Sep 27, 2019

Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
62.0
KEV listed

CVE-2018-15875

Published Aug 25, 2018

Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an Ad…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15874

Published Aug 25, 2018

Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname fie…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11436

Published Jul 19, 2017

D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7406

Published Jul 7, 2017

The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7405

Published Jul 7, 2017

On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the v…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2017-7404

Published Jul 7, 2017

On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9542

Published Jun 11, 2017

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Succ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7398

Published Apr 4, 2017

D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for wh…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2