Show filters
921 Total Results
Displaying 1-10 of 921
Sort by:
Attacker Value
Low
CVE-2020-12695 "CallStranger"
Disclosure Date: June 08, 2020 (last updated April 09, 2024)
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
2
Attacker Value
High
CVE-2023-33625
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
2
Attacker Value
Low
CVE-2020-25078
Disclosure Date: September 02, 2020 (last updated November 09, 2023)
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator password disclosure.
1
Attacker Value
High
CVE-2020-8864
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper handling of empty passwords. An attacker can leverage this vulnerability to execute arbitrary code on the router. Was ZDI-CAN-9471.
0
Attacker Value
Very Low
CVE-2020-8862
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC067 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. The issue results from the lack of proper password checking. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-10082.
0
Attacker Value
Very Low
CVE-2020-6842
Disclosure Date: February 21, 2020 (last updated February 21, 2025)
D-Link DCH-M225 1.05b01 and earlier devices allow remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the media renderer name.
0
Attacker Value
Low
CVE-2020-6841
Disclosure Date: February 21, 2020 (last updated February 21, 2025)
D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.
0
Attacker Value
Unknown
CVE-2025-25744
Disclosure Date: February 12, 2025 (last updated February 20, 2025)
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.
0
Attacker Value
Unknown
CVE-2025-25743
Disclosure Date: February 12, 2025 (last updated February 20, 2025)
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings module.
0
Attacker Value
Unknown
CVE-2025-25742
Disclosure Date: February 12, 2025 (last updated February 20, 2025)
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.
0