Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Dlink Dir-878 Firmware | 19/10/2022 | 17/6/2026 | D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi. | |
| Modificada | Alta (7.8) | 2.2% | — | Dlink Dir-1360 FirmwareDlink Dir-1760 FirmwareDlink Dir-1960 FirmwareDlink Dir-2640 Firmware+6 | 11/4/2022 | 17/6/2026 | A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root. | |
| Modificada | Alta (8.8) | 1.5% | — | Dlink Dir-878 Firmware | 7/4/2022 | 17/6/2026 | D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service. | |
| Modificada | Crítica (9.8) | 4.5% | — | Dlink Dir-878 Firmware | 4/2/2022 | 17/6/2026 | D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request. | |
| Modificada | Crítica (9.8) | 4.0% | — | Dlink Dir-878 FirmwareDlink Dir-882 Firmware | 4/2/2022 | 17/6/2026 | D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-878 Firmware | 2/4/2021 | 17/6/2026 | An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication. | |
| Modificada | Alta (8.8) | 2.8% | — | D-link Dir-867 FirmwareD-link Dir-878 FirmwareD-link Dir-882 Firmware | 23/7/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.20B10_BETA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP requests. The issue… | |
| Modificada | Alta (8.8) | 80% | — | Dlink Dir-878 FirmwareDlink Dir-882 FirmwareDlink Dir-867 Firmware | 23/3/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue… | |
| Modificada | Alta (8.8) | 77% | — | Dlink Dir-878 FirmwareDlink Dir-882 FirmwareDlink Dir-867 Firmware | 23/3/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue… | |
| Modificada | Crítica (9.8) | 3.0% | — | D-link Dir-878 Firmware | 25/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header. | |
| Modificada | Crítica (9.8) | 2.2% | — | D-link Dir-878 Firmware | 25/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password. | |
| Modificada | Alta (8.8) | 7.8% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 6.4% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 6.4% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 6.6% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 6.4% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 6.4% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 6.4% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… | |
| Modificada | Alta (8.8) | 7.0% | — | Dlink Dir-878 Firmware | 13/2/2019 | 17/6/2026 | An issue was discovered on D-Link DIR-878 devices with firmware 1.12A1. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST request. This occurs when… |