Show filters
68 Total Results
Displaying 61-68 of 68
Sort by:
Attacker Value
Unknown

CVE-2018-17068

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter.
0
Attacker Value
Unknown

CVE-2018-17065

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address.
0
Attacker Value
Unknown

CVE-2018-17067

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address.
0
Attacker Value
Unknown

CVE-2018-17066

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter.
0
Attacker Value
Unknown

CVE-2018-17064

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked.
0
Attacker Value
Unknown

CVE-2018-17063

Disclosure Date: September 15, 2018 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters.
0
Attacker Value
Unknown

CVE-2018-11013

Disclosure Date: May 13, 2018 (last updated November 26, 2024)
Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthenticated remote attackers to execute arbitrary code via a request with a long HTTP Host header.
0
Attacker Value
Unknown

CVE-2015-5999

Disclosure Date: November 18, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.
0