Skip to main content

Vendor archive

dlink CVEs

Beta · best-effort

1,765 CVEs tagged to vendor dlink462 Critical, 873 High, 342 Medium, 88 Low, 0 Unrated.

CVE-2016-10177

Published Jan 30, 2017

An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10125

Published Jan 9, 2017

D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.

CVSS 8.1 · High

CVE-2015-5999

Published Nov 18, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2052

Published Feb 23, 2015

Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-2051

Published Feb 23, 2015

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP…

CVSS 8.8 · High
evidence mentions
16
Buzz score
69.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2015-2050

Published Feb 23, 2015

D-Link DAP-1320 Rev Ax with firmware before 1.21b05 allows attackers to execute arbitrary commands via unspecified vectors.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2049

Published Feb 23, 2015

Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an ex…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2048

Published Feb 23, 2015

Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via u…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1028

Published Jan 21, 2015

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HT…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-10028

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in D-Link DAP-1360 router with firmware 2.5.4 and later allows remote attackers to inject arbitrary web script or HTML via the res_buf par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10027

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspeci…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10026

Published Jan 13, 2015

index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by setting the client_login cookie t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10025

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified us…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100005

Published Jan 13, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of a…

CVSS 8.0 · High
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2014-9517

Published Jan 5, 2015

Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7389

Published Jul 7, 2014

Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-4645

Published Jun 25, 2014

Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbitrary web script or HTML via a hostname.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,701-1,725 of 1,765 CVEsPage 69 of 71