Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 4.6% | — | Dlink Dir-645 Firmware | 18/9/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects… | |
| Modificada | Alta (7.4) | 3.3% | 💥 Exploit | Dlink Dir-825 Firmware | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be… | |
| Analizada | Baja (2.1) | 5.4% | — | Dlink Dir-852 Firmware | 18/9/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-852 1.00CN B09. This issue affects the function ssdpcgi_main of the file htodcs/cgibin of the component Simple Service Discovery Protocol Service. Executing manipulation of the argument ST can lead to command injection. The attack may be performed from remote. The exploit… | |
| Analizada | Baja (2.1) | 8.8% | — | Dlink Dir-852 Firmware | 18/9/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-852 1.00CN B09. This vulnerability affects unknown code of the file /htdocs/cgibin/hedwig.cgi of the component Web Management Interface. Performing manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and… | |
| Analizada | Baja (2.1) | 7.4% | — | Dlink Dir-823x Firmware | 18/9/2025 | 30/9/2026 | A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be… | |
| Aplazada | Baja (2.1) | 12% | — | Dlink Di-8100gAIDlink Di-8200gAIDlink Di-8003gAI | 15/9/2025 | 17/6/2026 | A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the file version_upgrade.asp of the component jhttpd. The manipulation of the argument path results in os command injection. The attack may be launched remotely. The exploit… | |
| Aplazada | Baja (2.1) | 12% | — | Dlink Di-8100AIDlink Di-8100gAIDlink Di-8200AIDlink Di-8200gAI+2 | 15/9/2025 | 17/6/2026 | A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by this vulnerability is the function sub_4621DC of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument hname leads to os command injection. The… | |
| Analizada | Baja (2.1) | 8.5% | — | Dlink Dir-823x Firmware | 14/9/2025 | 17/6/2026 | A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 4.7% | — | Dlink Dir-823x Firmware | 9/9/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed… | |
| Analizada | Media (5.5) | 1.0% | — | Dlink Dir-852 Firmware | 8/9/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability is the function phpcgi_main of the file /getcfg.php of the component Device Configuration Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploit is publicly… | |
| Analizada | Alta (7.4) | 0.97% | — | Dlink Dir-825 Firmware | 6/9/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of the argument ping6_ipaddr results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and… | |
| Analizada | Alta (7.4) | 1.5% | — | Dlink Di-8400 Firmware | 4/9/2025 | 17/6/2026 | A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the file /yyxz.asp. This manipulation of the argument ID causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Baja (0.9) | 27% | — | Dlink Di-7400g+ Firmware | 1/9/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to… | |
| Analizada | Media (5.5) | 17% | — | Dlink Dir-852 Firmware | 1/9/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Baja (2) | 10% | — | Dlink Di-500wf Firmware | 31/8/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DI-500WF 14.04.10A1T. The impacted element is an unknown function of the file /version_upgrade.asp of the component jhttpd. The manipulation of the argument path leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Baja (2.1) | 4.8% | — | Dlink Dir-816l Firmware | 31/8/2025 | 17/6/2026 | A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulation of the argument service causes os command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be… | |
| Analizada | Crítica (9.8) | 7.0% | — | Dlink Dir-868l Firmware | 28/8/2025 | 17/6/2026 | D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or… | |
| Analizada | Crítica (10) | 10% | — | Dlink Dir-110 FirmwareDlink Dir-412 FirmwareDlink Dir-600 FirmwareDlink Dir-610 Firmware+3 | 27/8/2025 | 17/6/2026 | Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input… | |
| Analizada | Media (6.6) | 0.24% | — | Dlink Dcs-825l Firmware | 27/8/2025 | 17/6/2026 | D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dcp` and `signalc` without verifying integrity, authenticity, or permissions. An attacker with local filesystem access (via physical access, firmware modification, or debug… | |
| Analizada | Alta (7.2) | 2.1% | — | Dlink Dsl-7740c Firmware | 25/8/2025 | 17/6/2026 | D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping6 function. | |
| Analizada | Alta (7) | 0.45% | — | Dlink Di-8100 Firmware | 25/8/2025 | 17/6/2026 | D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. This vulnerability allows authenticated attackers to cause a Denial of Service (DoS) by sending crafted GET requests with overly long values for these parameters. | |
| Analizada | Media (6.5) | 1.4% | — | Dlink Dsl-7740c Firmware | 25/8/2025 | 17/6/2026 | D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the ping function. | |
| Analizada | Media (5.3) | 0.59% | — | Dlink Dsl-7740c Firmware | 25/8/2025 | 17/6/2026 | Insecure default credentials for the Adminsitrator account of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to escalate privileges via a bruteforce attack. | |
| Analizada | Media (5.3) | 0.58% | — | Dlink Dsl-7740c Firmware | 25/8/2025 | 17/6/2026 | Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated attackers with low-level privileges to arbitrarily change the high-privileged account passwords and escalate privileges. | |
| Analizada | Media (5.3) | 1.7% | — | Dlink Dsl-7740c Firmware | 25/8/2025 | 17/6/2026 | A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request. |