CVE-2025-6334
- EPSS 0.05%
- Veröffentlicht 20.06.2025 11:00:17
- Zuletzt bearbeitet 11.07.2025 15:55:13
A vulnerability has been found in D-Link DIR-867 1.0 and classified as critical. This vulnerability affects the function strncpy of the component Query String Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated...
CVE-2023-24762
- EPSS 1.7%
- Veröffentlicht 13.03.2023 14:15:12
- Zuletzt bearbeitet 03.03.2025 20:15:38
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.
CVE-2022-41140
- EPSS 1.63%
- Veröffentlicht 26.01.2023 18:59:53
- Zuletzt bearbeitet 21.11.2024 07:22:41
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, w...
CVE-2022-1262
- EPSS 0.62%
- Veröffentlicht 11.04.2022 20:15:18
- Zuletzt bearbeitet 21.11.2024 06:40:21
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
CVE-2020-8863
- EPSS 1.77%
- Veröffentlicht 23.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:35
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific ...
CVE-2020-8864
- EPSS 11.33%
- Veröffentlicht 23.03.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:35
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific ...