CVE-2018-25115
- EPSS 0.52%
- Published 27.08.2025 21:24:23
- Last modified 24.09.2025 18:03:34
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system comman...
CVE-2013-10069
- EPSS 5.03%
- Published 05.08.2025 20:01:04
- Last modified 23.09.2025 18:37:48
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command injection vulnerability in command.php, which improperly handles the cmd POST parameter. A remote attac...
CVE-2013-10048
- EPSS 1.93%
- Published 01.08.2025 20:39:20
- Last modified 23.09.2025 17:41:57
An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending spe...
CVE-2024-7357
- EPSS 0.79%
- Published 01.08.2024 13:15:10
- Last modified 16.07.2025 13:53:45
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. This issue affects the function soapcgi_main of the file /soap.cgi. The manipulation of the argument service leads to os command in...
CVE-2023-33625
- EPSS 89.18%
- Published 12.06.2023 20:15:12
- Last modified 21.11.2024 08:05:46
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.
CVE-2023-33626
- EPSS 1.63%
- Published 12.06.2023 20:15:12
- Last modified 21.11.2024 08:05:46
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.
CVE-2013-7471
- EPSS 29.65%
- Published 11.06.2019 21:29:00
- Last modified 21.11.2024 02:01:05
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalCli...
CVE-2014-100005
- EPSS 35.43%
- Published 13.01.2015 11:59:04
- Last modified 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or ...