Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2021-29296
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Null Pointer Dereference vulnerability in D-Link DIR-825 2.10b02, which could let a remote malicious user cause a denial of service. The vulnerability could be triggered by sending an HTTP request with URL /vct_wan; the sbin/httpd would invoke the strchr function and take NULL as a first argument, which finally leads to the segmentation fault. NOTE: The DIR-825 and all hardware revisions is considered End of Life and as such this issue will not be patched
0
Attacker Value
Unknown
CVE-2020-10214
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is a stack-based buffer overflow in the httpd binary. It allows an authenticated user to execute arbitrary code via a POST to ntp_sync.cgi with a sufficiently long parameter ntp_server.
0
Attacker Value
Unknown
CVE-2020-10213
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
0
Attacker Value
Unknown
CVE-2020-10216
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
0
Attacker Value
Unknown
CVE-2020-10215
Disclosure Date: March 07, 2020 (last updated February 21, 2025)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected.
0
Attacker Value
Unknown
CVE-2019-9122
Disclosure Date: February 25, 2019 (last updated November 27, 2024)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the ntp_server parameter in an ntp_sync.cgi POST request.
0
Attacker Value
Unknown
CVE-2019-9126
Disclosure Date: February 25, 2019 (last updated November 09, 2023)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via requests for the router_info.xml document. This will reveal the PIN code, MAC address, routing table, firmware version, update time, QOS information, LAN information, and WLAN information of the device.
0
Attacker Value
Unknown
CVE-2019-9123
Disclosure Date: February 25, 2019 (last updated November 09, 2023)
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
0