Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 6.1% | — | Dlink Dir-823x Firmware | 22/9/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-823X 240126/240802/250416. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/goahead. This manipulation of the argument port causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 7.4% | — | Dlink Dir-823x Firmware | 18/9/2025 | 30/9/2026 | A weakness has been identified in D-Link DIR-823X 240126/240802/250416. The impacted element is the function sub_412E7C of the file /usr/sbin/goahead of the component Environment Variable Handler. This manipulation of the argument terminal_addr/server_ip/server_port causes command injection. The attack can be… | |
| Analizada | Baja (2.1) | 8.5% | — | Dlink Dir-823x Firmware | 14/9/2025 | 17/6/2026 | A vulnerability was detected in D-Link DIR-823x up to 250416. The affected element is an unknown function of the file /goform/diag_ping. Performing manipulation of the argument target_addr results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 4.7% | — | Dlink Dir-823x Firmware | 9/9/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed… | |
| Analizada | Alta (7.2) | 1.3% | — | Dlink Dir-823x Firmware | 17/4/2025 | 17/6/2026 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8 | |
| Analizada | Crítica (9.8) | 1.8% | — | Dlink Dir-823x Firmware | 17/4/2025 | 17/6/2026 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234 | |
| Analizada | Crítica (9.8) | 2.3% | — | Dlink Dir-823x Firmware | 17/4/2025 | 17/6/2026 | An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-823x Firmware | 17/4/2025 | 17/6/2026 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-823x Firmware | 17/4/2025 | 17/6/2026 | An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c | |
| Analizada | Alta (7.2) | 88% | ⚠ Explotación activa💥 Exploit | Dlink Dir-823x Firmware | 25/3/2025 | 17/6/2026 | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution. | |
| Analizada | Media (5.1) | 4.5% | — | Dlink Dir-823x Firmware | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument target_addr leads to os command injection. The attack may be… | |
| Analizada | Alta (7.1) | 14% | — | Dlink Dir-823x Firmware | 7/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the function set_wifi_blacklists of the file /goform/set_wifi_blacklists of the component HTTP POST Request Handler. The manipulation of the argument macList leads to null pointer dereference. It is possible… | |
| Analizada | Alta (8.7) | 1.9% | — | Dlink Dir-823x Firmware | 15/1/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-823X 240126/240802 and classified as critical. Affected by this vulnerability is the function FUN_00412244. The manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Crítica (9.8) | 2.1% | — | Dlink Dir-823x Firmware | 19/7/2024 | 17/6/2026 | D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request. |