Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.8%—Dlink Dir-878 Firmware19/10/202217/6/2026
D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
ModificadaAlta (7.8)2.2%—Dlink Dir-1360 FirmwareDlink Dir-1760 FirmwareDlink Dir-1960 FirmwareDlink Dir-2640 Firmware+611/4/202217/6/2026
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
ModificadaAlta (8.8)1.5%—Dlink Dir-878 Firmware7/4/202217/6/2026
D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.
ModificadaCrítica (9.8)4.5%—Dlink Dir-878 Firmware4/2/202217/6/2026
D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
ModificadaCrítica (9.8)4.0%—Dlink Dir-878 FirmwareDlink Dir-882 Firmware4/2/202217/6/2026
D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.
ModificadaCrítica (9.8)1.4%—Dlink Dir-878 Firmware2/4/202117/6/2026
An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.
ModificadaAlta (8.8)2.8%—D-link Dir-867 FirmwareD-link Dir-878 FirmwareD-link Dir-882 Firmware23/7/202017/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.20B10_BETA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP requests. The issue…
ModificadaAlta (8.8)80%—Dlink Dir-878 FirmwareDlink Dir-882 FirmwareDlink Dir-867 Firmware23/3/202017/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue…
ModificadaAlta (8.8)77%—Dlink Dir-878 FirmwareDlink Dir-882 FirmwareDlink Dir-867 Firmware23/3/202017/6/2026
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue…
ModificadaCrítica (9.8)3.0%—D-link Dir-878 Firmware25/2/201917/6/2026
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.
ModificadaCrítica (9.8)2.2%—D-link Dir-878 Firmware25/2/201917/6/2026
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.
ModificadaAlta (8.8)7.8%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)6.4%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)6.4%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)6.6%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)6.4%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)6.4%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)6.4%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
ModificadaAlta (8.8)7.0%—Dlink Dir-878 Firmware13/2/201917/6/2026
An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when…
Orbitaley — Vulnerabilidades