CVE-2021-39510
- EPSS 6.5%
- Veröffentlicht 24.08.2021 19:15:33
- Zuletzt bearbeitet 21.11.2024 06:19:34
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. Th...
CVE-2021-39509
- EPSS 16.34%
- Veröffentlicht 24.08.2021 19:15:32
- Zuletzt bearbeitet 21.11.2024 06:19:34
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This ...
CVE-2021-27114
- EPSS 1.86%
- Veröffentlicht 14.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:22
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the retu...
- EPSS 30.98%
- Veröffentlicht 14.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:21
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters...
- EPSS 34.28%
- Veröffentlicht 30.03.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:56:51
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell me...
CVE-2019-7642
- EPSS 10.87%
- Veröffentlicht 25.03.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:27
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions...
CVE-2019-10039
- EPSS 1.21%
- Veröffentlicht 25.03.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:18:15
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setSysAdm to edit the web or system account without authentication.
CVE-2019-10042
- EPSS 0.79%
- Veröffentlicht 25.03.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:18:16
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.
CVE-2019-10041
- EPSS 0.92%
- Veröffentlicht 25.03.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:18:15
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.
- EPSS 1.3%
- Veröffentlicht 25.03.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:18:15
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /goform/SystemCommand to execute a system command without authentication.