Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Total 1765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48634 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2026-06-17 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48633 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2026-06-17 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48632 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2026-06-17 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48631 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2026-06-17 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48630 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2026-06-17 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48629 1 Dlink 4 Dir-878, Dir-878 Firmware, Dir-882 and 1 more 2026-06-17 N/A 8.0 HIGH
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
CVE-2024-48272 1 Dlink 2 Dsl-6740c, Dsl-6740c Firmware 2026-06-17 N/A 6.5 MEDIUM
D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.
CVE-2024-48271 1 Dlink 2 Dsl-6740c, Dsl-6740c Firmware 2026-06-17 N/A 8.8 HIGH
D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.
CVE-2024-48168 1 Dlink 2 Dcs-960l, Dcs-960l Firmware 2026-06-17 N/A 9.8 CRITICAL
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.
CVE-2024-48150 1 Dlink 2 Dir-820l, Dir-820l Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
CVE-2024-45698 1 Dlink 2 Dir-x4860, Dir-x4860 Firmware 2026-06-17 N/A 9.8 CRITICAL
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.
CVE-2024-45697 1 Dlink 2 Dir-x4860, Dir-x4860 Firmware 2026-06-17 N/A 9.8 CRITICAL
Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote attackers can log in and execute OS commands using hard-coded credentials.
CVE-2024-45696 1 Dlink 4 Covr-x1870, Covr-x1870 Firmware, Dir-x4860 and 1 more 2026-06-17 N/A 8.8 HIGH
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device.
CVE-2024-45695 1 Dlink 2 Dir-x4860, Dir-x4860 Firmware 2026-06-17 N/A 9.8 CRITICAL
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
CVE-2024-45694 1 Dlink 4 Dir-x4860, Dir-x4860 Firmware, Dir-x5460 and 1 more 2026-06-17 N/A 9.8 CRITICAL
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
CVE-2024-44674 1 Dlink 2 Covr-2600r, Covr-2600r Firmware 2026-06-17 N/A 5.7 MEDIUM
D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.
CVE-2024-44589 1 Dlink 2 Dcs-960l, Dcs-960l Firmware 2026-06-17 N/A 8.8 HIGH
Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.
CVE-2024-44411 1 Dlink 2 Di-8300, Di-8300 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
CVE-2024-44410 1 Dlink 2 Di-8300, Di-8300 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
CVE-2024-44408 1 Dlink 2 Dir-823g, Dir-823g Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.