Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Total 1765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-55611 1 Dlink 2 Dir-619l, Dir-619l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.
CVE-2025-55602 1 Dlink 2 Dir-619l, Dir-619l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.
CVE-2025-55599 1 Dlink 2 Dir-619l, Dir-619l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.
CVE-2025-55583 1 Dlink 2 Dir-868l, Dir-868l Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.
CVE-2025-55582 1 Dlink 2 Dcs-825l, Dcs-825l Firmware 2026-06-17 N/A 6.6 MEDIUM
D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug interfaces) can replace these binaries with malicious payloads. The script executes these binaries as root in an infinite loop, leading to persistent privilege escalation and arbitrary code execution. This issue is mitigated in v1.09.02, but the product is officially End-of-Life and unsupported.
CVE-2025-55581 1 Dlink 2 Dcs-825l, Dcs-825l Firmware 2026-06-17 N/A 7.3 HIGH
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The script monitors and respawns the `dcp` and `signalc` binaries without validating their integrity, origin, or permissions. An attacker with filesystem access (e.g., via UART or firmware modification) may replace these binaries to achieve persistent arbitrary code execution with root privileges. The issue stems from improper handling of executable trust and absence of integrity checks in the watchdog logic.
CVE-2025-52222 1 Dlink 18 Di-8003, Di-8003 Firmware, Di-8003g and 15 more 2026-06-17 N/A 7.5 HIGH
D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
CVE-2025-52079 1 Dlink 2 Dir-820l, Dir-820l Firmware 2026-06-17 N/A 8.8 HIGH
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
CVE-2025-51385 1 Dlink 2 Di-8200, Di-8200 Firmware 2026-06-17 N/A 3.5 LOW
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the id parameter.
CVE-2025-51384 1 Dlink 2 Di-8200, Di-8200 Firmware 2026-06-17 N/A 3.5 LOW
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
CVE-2025-51383 1 Dlink 2 Di-8200, Di-8200 Firmware 2026-06-17 N/A 3.5 LOW
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
CVE-2025-51281 1 Dlink 2 Di-8100, Di-8100 Firmware 2026-06-17 N/A 7.0 HIGH
D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability allows authenticated attackers to cause a Denial of Service (DoS) by sending crafted GET requests with overly long values for these parameters.
CVE-2025-50673 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.
CVE-2025-50672 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.
CVE-2025-50671 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters name, en, user_id, shibie_name, time, act, log, and rpri.
CVE-2025-50670 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, and time parameters.
CVE-2025-50669 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.
CVE-2025-50668 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.
CVE-2025-50667 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.
CVE-2025-50666 1 Dlink 2 Di-8003, Di-8003 Firmware 2026-06-17 N/A 7.5 HIGH
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.