Dlink
Dlink Dir-615 Firmware: vulnerabilidades y CVE
Dlink Dir-615 Firmware tiene 19 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 6 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses5
Críticas6
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-8361 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 may 2015 | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. |
| CVE-2019-16920 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 sept 2019 | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2152 | Alta (7.3) | 4.8% | — | 8 feb 2026 | A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/… |
| CVE-2026-2151 | Alta (7.3) | 4.7% | — | 8 feb 2026 | A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr leads to os command… |
| CVE-2026-1506 | Alta (7.3) | 5.6% | — | 28 ene 2026 | A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command… |
| CVE-2026-1505 | Alta (7.3) | 5.1% | — | 28 ene 2026 | A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can… |
| CVE-2026-1448 | Alta (7.3) | 5.8% | — | 27 ene 2026 | A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument… |
| CVE-2018-25115 | Crítica (10) | 10% | — | 27 ago 2025 | Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to… |
| CVE-2013-10050 | Alta (8.7) | 14% | — | 1 ago 2025 | An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly… |
| CVE-2024-0717 | Media (5.3) | 18% | — | 19 ene 2024 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825,… |
| CVE-2021-42627 | Crítica (9.8) | 63% | — | 23 ago 2022 | The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker… |
| CVE-2021-40654 | Media (6.5) | 1.9% | — | 24 sept 2021 | An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page |
| CVE-2021-37388 | Crítica (9.8) | 3.7% | — | 6 ago 2021 | A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution. |
| CVE-2019-17525 | Alta (8.8) | 5.8% | — | 21 abr 2020 | The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks. |
| CVE-2019-19742 | Media (4.8) | 20% | — | 18 dic 2019 | On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. |
| CVE-2019-17353 | Alta (8.2) | 3.0% | — | 9 oct 2019 | An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be… |
| CVE-2019-16920 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 sept 2019 | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway… |
| CVE-2018-15839 | Crítica (9.8) | 45% | — | 28 ago 2018 | D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header. |
| CVE-2018-15875 | Media (6.1) | 1.2% | — | 25 ago 2018 | Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request. |
| CVE-2018-15874 | Media (6.1) | 1.2% | — | 25 ago 2018 | Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request. |
| CVE-2014-8361 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 may 2015 | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.