Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 11% | — | Dlink Dir-605 Firmware | 18/12/2025 | 1/10/2026 | A vulnerability was detected in D-Link DIR-605 202WWB03. Affected by this issue is some unknown functionality of the component Firmware Update Service. Performing manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects… | |
| Analizada | Alta (8.7) | 0.73% | — | Dlink Dap-1325 Firmware | 16/12/2025 | 17/6/2026 | D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly… | |
| Analizada | Alta (7.4) | 3.8% | 💥 PoC | Dlink Dir-868l B1 FirmwareDlink Dir-860l B1 Firmware | 14/12/2025 | 7/10/2026 | A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 4.0% | 💥 Exploit | Dlink Dir-803 Firmware | 11/12/2025 | 7/10/2026 | A vulnerability was detected in D-Link DIR-803 up to 1.04. Impacted is an unknown function of the file /getcfg.php of the component Configuration Handler. The manipulation of the argument AUTHORIZED_GROUP results in information disclosure. The attack may be performed from remote. The exploit is now public and may be… | |
| Aplazada | Alta (8.7) | 0.37% | — | Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI | 9/12/2025 | 17/6/2026 | A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device. | |
| Analizada | Baja (2.1) | 8.9% | — | Dlink Dcs-930l Firmware | 8/12/2025 | 7/10/2026 | A vulnerability was determined in D-Link DCS-930L 1.15.04. This affects an unknown part of the file /setSystemAdmin of the component alphapd. Executing manipulation of the argument AdminID can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.… | |
| Analizada | Baja (2.1) | 3.4% | — | Dlink Dir-823x Firmware | 8/12/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-823X up to 20250416. This affects the function sub_415028 of the file /goform/set_wan_settings. The manipulation of the argument ppp_username results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may… | |
| Analizada | Crítica (9.8) | 1.2% | 💥 PoC | Dlink R15 Firmware | 2/12/2025 | 17/6/2026 | A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd. | |
| Analizada | Media (5.5) | 6.2% | — | Dlink Dir-852 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects… | |
| Analizada | Alta (7.4) | 0.70% | — | Dlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (7.4) | 0.76% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released… | |
| Analizada | Alta (7.4) | 0.76% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Analizada | Alta (7.4) | 0.76% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Analizada | Alta (7.4) | 0.73% | — | Dlink Dir-822k Firmware | 23/11/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNtp. Performing manipulation of the argument submit-url results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.4) | 0.74% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.3) | 7.6% | — | Dlink Dir-868l Firmware | 19/11/2025 | 17/6/2026 | D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command. | |
| Analizada | Baja (2.1) | 8.3% | — | Dlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dir-822k FirmwareDlink Dir-825m Firmware | 18/11/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Alta (7.4) | 3.6% | — | Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+1 | 17/11/2025 | 17/6/2026 | A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has… | |
| Analizada | Alta (7.4) | 0.81% | — | Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+1 | 17/11/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.90% | — | Dlink Dir-816l Firmware | 15/11/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the file /soap.cgi. This manipulation causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only… | |
| Analizada | Alta (7.4) | 0.82% | — | Dlink Dir-816l Firmware | 15/11/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the file /portal/__ajax_exporer.sgi. The manipulation of the argument en results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be… | |
| Analizada | Alta (7.4) | 0.90% | — | Dlink Dir-816l Firmware | 15/11/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.9) | 2.4% | — | Dlink Dir-816l Firmware | 14/11/2025 | 17/6/2026 | A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument Password results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is… | |
| Modificada | Alta (8.8) | 0.67% | — | Dlink Dir-816 Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated using sprintf() into… |