Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Total 1765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2619 1 Dlink 2 Dap-1620, Dap-1620 Firmware 2026-06-17 10.0 HIGH 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2618 1 Dlink 2 Dap-1620, Dap-1620 Firmware 2026-06-17 10.0 HIGH 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the function set_ws_action of the file /dws/api/ of the component Path Handler. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2553 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been rated as problematic. This issue affects some unknown processing of the file /goform/formVirtualServ. The manipulation leads to improper access controls. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2552 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been declared as problematic. This vulnerability affects unknown code of the file /goform/formTcpipSetup. The manipulation leads to improper access controls. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2551 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02. It has been classified as problematic. This affects an unknown part of the file /goform/formSetPortTr. The manipulation leads to improper access controls. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2550 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability was found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this issue is some unknown functionality of the file /goform/formSetDDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2549 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability has been found in D-Link DIR-618 and DIR-605L 2.02/3.02 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /goform/formSetPassword. The manipulation leads to improper access controls. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2548 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in D-Link DIR-618 and DIR-605L 2.02/3.02. Affected is an unknown function of the file /goform/formSetDomainFilter. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2547 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability, which was classified as problematic, has been found in D-Link DIR-618 and DIR-605L 2.02/3.02. This issue affects some unknown processing of the file /goform/formAdvNetwork. The manipulation leads to improper access controls. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2546 1 Dlink 4 Dir-605l, Dir-605l Firmware, Dir-618 and 1 more 2026-06-17 3.3 LOW 4.3 MEDIUM
A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall Service. The manipulation leads to improper access controls. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2360 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-2359 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-29743 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
CVE-2025-29635 1 Dlink 2 Dir-823x, Dir-823x Firmware 2026-06-17 N/A 7.2 HIGH
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
CVE-2025-29523 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 7.2 HIGH
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function.
CVE-2025-29522 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function.
CVE-2025-29521 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 5.3 MEDIUM
Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack.
CVE-2025-29520 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 5.3 MEDIUM
Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account passwords and escalate privileges.
CVE-2025-29519 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 5.3 MEDIUM
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.
CVE-2025-29517 1 Dlink 2 Dsl-7740c, Dsl-7740c Firmware 2026-06-17 N/A 6.8 MEDIUM
D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.