CVE-2013-10069
- EPSS 5.03%
- Published 05.08.2025 20:01:04
- Last modified 23.09.2025 18:37:48
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attac...
CVE-2013-10048
- EPSS 1.93%
- Published 01.08.2025 20:39:20
- Last modified 23.09.2025 17:41:57
An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending spe...
CVE-2013-10050
- EPSS 0.35%
- Published 01.08.2025 20:39:00
- Last modified 23.09.2025 17:38:12
An OS command injection vulnerability exists in multiple D-Link routers—confirmed on DIR-300 rev A (v1.05) and DIR-615 rev D (v4.13)—via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in...
CVE-2024-41616
- EPSS 0.25%
- Published 06.08.2024 16:15:49
- Last modified 07.08.2024 20:54:20
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
CVE-2024-0717
- EPSS 28.39%
- Published 19.01.2024 16:15:11
- Last modified 21.11.2024 08:47:12
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, D...
CVE-2023-31814
- EPSS 0.18%
- Published 23.05.2023 01:15:10
- Last modified 17.01.2025 18:15:23
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
CVE-2013-7471
- EPSS 29.65%
- Published 11.06.2019 21:29:00
- Last modified 21.11.2024 02:01:05
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalCli...