Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 2.1% | — | Dlink Dwr-m961 Firmware | 29/1/2026 | 17/6/2026 | A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 3.8% | — | Dlink Dir-823x Firmware | 28/1/2026 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-823X 250416. Impacted is the function sub_41E2A0 of the file /goform/set_mode. Performing a manipulation of the argument lan_gateway results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may… | |
| Analizada | Baja (1.9) | 0.68% | — | Dlink Dcs-700l Firmware | 28/1/2026 | 17/6/2026 | A vulnerability was identified in D-Link DCS-700L 1.03.09. The affected element is the function uploadmusic of the file /setUploadMusic of the component Music File Upload Service. The manipulation of the argument UploadMusic leads to path traversal. The attack can only be initiated within the local network. The… | |
| Analizada | Alta (7.3) | 5.6% | — | Dlink Dir-615 Firmware | 28/1/2026 | 17/6/2026 | A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed… | |
| Analizada | Alta (7.3) | 5.1% | — | Dlink Dir-615 Firmware | 28/1/2026 | 17/6/2026 | A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only… | |
| Analizada | Alta (7.3) | 5.8% | — | Dlink Dir-615 Firmware | 27/1/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is… | |
| Analizada | Baja (2) | 17% | — | Dlink Dcs-700l Firmware | 26/1/2026 | 17/6/2026 | A weakness has been identified in D-Link DCS700l 1.03.09. Affected is an unknown function of the file /setDayNightMode of the component Web Form Handler. Executing a manipulation of the argument LightSensorControl can lead to command injection. The attack may be launched remotely. The exploit has been made available… | |
| Analizada | Alta (8.4) | 0.17% | — | Dlink D-view 8 | 21/1/2026 | 17/6/2026 | D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the… | |
| Analizada | Alta (8.7) | 0.38% | — | Dlink D-view 8 | 21/1/2026 | 17/6/2026 | D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be… | |
| Modificada | Media (5.5) | 16% | — | Dlink Dir-823x Firmware | 18/1/2026 | 17/6/2026 | A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made available to the public… | |
| Analizada | Crítica (9.8) | 9.7% | — | Dlink Dir-895la1 Firmware | 9/1/2026 | 17/6/2026 | A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an… | |
| Analizada | Baja (2.1) | 12% | — | Dlink Di-8200g Firmware | 9/1/2026 | 17/6/2026 | A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (6.8) | 0.43% | 💥 PoC | Dlink Dir-605l Firmware | 8/1/2026 | 17/6/2026 | An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access control. | |
| Aplazada | Crítica (9.3) | 0.97% | — | Dlink DSLAIDlink DIRAIDlink DNSAI | 5/1/2026 | 17/6/2026 | Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the device’s DNS settings without… | |
| Analizada | Baja (2.1) | 4.2% | — | Dlink Dir-806a Firmware | 31/12/2025 | 23/9/2026 | A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. This vulnerability only… | |
| Analizada | Baja (2.1) | 4.6% | — | Dlink Di-7400g+ Firmware | 30/12/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2) | 0.61% | — | Dlink Dcs-850l Firmware | 30/12/2025 | 7/10/2026 | A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path traversal. The attack must originate from the local network. The exploit has been made public and could be used. This… | |
| Analizada | Alta (8.9) | 1.2% | — | Dlink Dir-600 Firmware | 29/12/2025 | 7/10/2026 | A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 7/10/2026 | A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 4.1% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 7/10/2026 | A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly… | |
| Analizada | Baja (2.1) | 4.1% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 7/10/2026 | A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the file /boafrm/formLtefotaUpgradeFibocom. This manipulation of the argument fota_url causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the… | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 7/10/2026 | A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42261C of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be exploited. | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 7/10/2026 | A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /boafrm/formDefRoute. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.1) | 0.16% | — | Ecessa Shieldlink Sl175ehqAI | 24/12/2025 | 17/6/2026 | Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator into loading the page. | |
| Analizada | Alta (8.8) | 0.53% | — | Dlink Dsl-124 Firmware | 22/12/2025 | 17/6/2026 | D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network… |