Show filters
922 Total Results
Displaying 241-250 of 922
Sort by:
Attacker Value
Unknown

CVE-2023-39637

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
Attacker Value
Unknown

CVE-2020-19323

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required
Attacker Value
Unknown

CVE-2020-19320

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.
Attacker Value
Unknown

CVE-2020-19319

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.
Attacker Value
Unknown

CVE-2020-19318

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows authorized attackers execute arbitrary code via sending crafted data to the webserver service program.
Attacker Value
Unknown

CVE-2023-4711

Disclosure Date: September 01, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230819. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-238574 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-4542

Disclosure Date: August 25, 2023 (last updated February 25, 2025)
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-39750

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.
Attacker Value
Unknown

CVE-2023-39749

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.
Attacker Value
Unknown

CVE-2023-39674

Disclosure Date: August 18, 2023 (last updated February 25, 2025)
D-Link DIR-880 A1_FW107WWb08 was discovered to contain a buffer overflow via the function fgets.