Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.43% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request. | |
| Analizada | Media (6.5) | 0.57% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request. | |
| Analizada | Media (6.5) | 0.43% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request. | |
| Analizada | Media (6.9) | 0.99% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 1.1% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (6.9) | 27% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.80% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/form2Dhcpd.cgi of the component DHCPD Setting Handler. The manipulation leads to improper access controls. The attack can be launched… | |
| Analizada | Media (6.9) | 0.74% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. Affected is an unknown function of the file /goform/form2AdvanceSetup.cgi of the component WiFi Settings Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely.… | |
| Analizada | Media (6.9) | 0.83% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This issue affects some unknown processing of the file /goform/form2AddVrtsrv.cgi of the component Virtual Service Handler. The manipulation leads to improper access controls. The attack may be initiated… | |
| Analizada | Media (6.9) | 0.80% | — | Dlink Dir-816 Firmware | 2/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. This vulnerability affects unknown code of the file /goform/DDNS of the component DDNS Service. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.8) | 2.1% | — | Dlink Dir-816 Firmware | 21/2/2024 | 17/6/2026 | Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dlink Dir-816 Firmware | 8/2/2024 | 9/7/2026 | An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function. | |
| Modificada | Media (5.3) | 18% | — | Dlink Dir-825acg1 FirmwareDlink Dir-841 FirmwareDlink Dir-1260 FirmwareDlink Dir-822 Firmware+40 | 19/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882,… | |
| Modificada | Crítica (9.8) | 2.1% | — | Dlink Dir-816 Firmware | 12/9/2023 | 9/7/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-816 Firmware | 26/10/2022 | 17/6/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-816 Firmware | 26/10/2022 | 17/6/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-816 Firmware | 26/10/2022 | 17/6/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-816 Firmware | 26/10/2022 | 17/6/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4. | |
| Modificada | Alta (7.5) | 2.7% | — | Dlink Dir-816 Firmware | 26/10/2022 | 17/6/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-816 Firmware | 26/10/2022 | 17/6/2026 | D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd. | |
| Modificada | Crítica (9.8) | 27% | — | Dlink Dir-816 Firmware | 31/8/2022 | 17/6/2026 | In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability | |
| Modificada | Alta (8.8) | 8.3% | — | Dlink Dir-816 Firmware | 31/8/2022 | 17/6/2026 | D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection. | |
| Modificada | Alta (8.8) | 2.7% | — | Dlink Dir-816 Firmware | 31/8/2022 | 17/6/2026 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi. | |
| Modificada | Alta (7.5) | 1.2% | — | Dlink Dir-816 Firmware | 31/8/2022 | 17/6/2026 | In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC. | |
| Modificada | Crítica (9.8) | 3.2% | — | Dlink Dir-816 Firmware | 31/8/2022 | 17/6/2026 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. |