Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)1.0%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)1.0%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the StartTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)1.0%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)0.99%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the MacAddress parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)1.1%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Type parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)1.0%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)1.0%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.5)0.93%—Dlink Dir-823g Firmware5/10/202317/6/2026
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaCrítica (9.8)1.3%—Dlink Dir-823g Firmware21/9/202317/6/2026
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.
ModificadaCrítica (9.8)1.3%—Dlink Dir-823g Firmware21/9/202317/6/2026
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.
ModificadaCrítica (9.8)1.3%—Dlink Dir-823g Firmware29/6/202317/6/2026
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.
ModificadaCrítica (9.8)31%—Dlink Dir-823g Firmware29/6/202317/6/2026
An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.
ModificadaCrítica (9.8)1.3%—Dlink Dir-823g Firmware29/6/202317/6/2026
D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.
ModificadaAlta (7.5)0.90%—Dlink Dir-823g Firmware28/6/202317/6/2026
D-Link DIR-823G firmware version 1.02B05 has a password reset vulnerability, which originates from the SetMultipleActions API, allowing unauthorized attackers to reset the WEB page management password.
ModificadaCrítica (9.8)1.2%—Dlink Dir-823g Firmware17/4/202317/6/2026
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
ModificadaCrítica (9.8)3.8%—Dlink Dir-823g Firmware22/11/202217/6/2026
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command…
ModificadaCrítica (9.8)1.3%—Dlink Dir-823g Firmware22/11/202217/6/2026
D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
ModificadaCrítica (9.8)3.7%—Dlink Dir-823g Firmware3/11/202217/6/2026
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
ModificadaCrítica (9.8)3.1%—Dlink Dir-823g Firmware7/4/202217/6/2026
An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function
ModificadaCrítica (9.8)8.6%—Dlink Dir-823g Firmware4/11/20219/7/2026
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
ModificadaCrítica (9.1)2.5%—Dlink Dir-823g Firmware4/11/20219/7/2026
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
ModificadaCrítica (9.8)8.6%—Dlink Dir-823g Firmware4/11/20219/7/2026
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
ModificadaAlta (8.8)4.3%—Dlink Dir-823g Firmware23/8/201917/6/2026
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
ModificadaAlta (8.8)7.7%—Dlink Dir-823g Firmware23/8/201917/6/2026
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
Orbitaley — Vulnerabilidades