CVE-2025-55583
- EPSS 0.82%
- Veröffentlicht 28.08.2025 00:00:00
- Zuletzt bearbeitet 09.09.2025 18:41:54
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-...
CVE-2023-39668
- EPSS 0.26%
- Veröffentlicht 18.08.2023 03:15:22
- Zuletzt bearbeitet 21.11.2024 08:15:47
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
CVE-2023-39667
- EPSS 0.26%
- Veröffentlicht 18.08.2023 03:15:22
- Zuletzt bearbeitet 21.11.2024 08:15:47
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
CVE-2023-39665
- EPSS 0.26%
- Veröffentlicht 18.08.2023 03:15:21
- Zuletzt bearbeitet 21.11.2024 08:15:47
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
CVE-2023-29856
- EPSS 0.27%
- Veröffentlicht 02.05.2023 15:15:23
- Zuletzt bearbeitet 21.11.2024 07:57:35
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.
CVE-2020-29321
- EPSS 1.03%
- Veröffentlicht 04.06.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:23:54
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
CVE-2019-20213
- EPSS 0.84%
- Veröffentlicht 02.01.2020 14:16:36
- Zuletzt bearbeitet 21.11.2024 04:38:13
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
- EPSS 93.19%
- Veröffentlicht 30.12.2019 17:15:19
- Zuletzt bearbeitet 03.04.2025 20:05:08
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when co...
CVE-2017-14948
- EPSS 4.78%
- Veröffentlicht 14.10.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 03:13:49
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request han...
CVE-2019-16190
- EPSS 0.9%
- Veröffentlicht 09.09.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:14
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.