Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1843 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.7% | — | Dlink Dir-822aAI | 7/9/2026 | 8/9/2026 | A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Media (5.5) | 2.3% | — | Dlink Dir-895lAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-320AI | 3/9/2026 | 4/9/2026 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly… | |
| Aplazada | Alta (8.6) | 3.3% | — | Dlink Dns-340lAI | 3/9/2026 | 4/9/2026 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The… | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-340lAI | 3/9/2026 | 4/9/2026 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the… | |
| Aplazada | Alta (8.6) | 3.3% | — | Dlink Dns-340lAIDlink Dns-345AI | 31/8/2026 | 31/8/2026 | A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-320lAIDlink Dns-327lAIDlink Dns-340lAIDlink Dns-345AI | 31/8/2026 | 2/9/2026 | A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed… | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-327lAIDlink Dns-340lAI | 31/8/2026 | 31/8/2026 | A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and… | |
| Aplazada | Alta (8.6) | 3.3% | — | Dlink Dns-320lAIDlink Dns-327lAIDlink Dns-340lAIDlink Dns-345AI | 31/8/2026 | 31/8/2026 | A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely.… | |
| Aplazada | Alta (8.5) | 3.6% | — | Dlink Dns-340lAIDlink Dns-345AI | 31/8/2026 | 1/9/2026 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote… | |
| Aplazada | Alta (7.4) | 0.84% | — | Dlink Dsm-g600AI | 31/8/2026 | 31/8/2026 | A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (2.1) | 4.4% | — | Dlink Dir-825mAI | 31/8/2026 | 31/8/2026 | A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (8.6) | 0.91% | — | Dlink Dir-825mAI | 31/8/2026 | 1/9/2026 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Aplazada | Alta (8.6) | 0.91% | — | Dlink Dir-825mAI | 30/8/2026 | 31/8/2026 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now… | |
| Aplazada | Alta (8.1) | 0.22% | — | Dlink Di-8100gAI | 24/8/2026 | 29/9/2026 | In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. | |
| Aplazada | Alta (8.1) | 0.22% | — | Dlink Di-7001 Mini 5GAI | 24/8/2026 | 29/9/2026 | D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands. | |
| Aplazada | Baja (2.3) | 0.47% | — | VsftpdAIDlink Dir-842AI | 15/8/2026 | 20/8/2026 | A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Dlink Dwr-m961AI | 8/8/2026 | 28/8/2026 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Dlink Dwr-m961AI | 8/8/2026 | 31/8/2026 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the… | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Dwr-m961AI | 8/8/2026 | 31/8/2026 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges. | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Dwr-m961AI | 8/8/2026 | 28/8/2026 | D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command… | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Dwr-m961AI | 8/8/2026 | 28/8/2026 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution… | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Dwr-m961AI | 8/8/2026 | 28/8/2026 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Dwr-m961AI | 8/8/2026 | 31/8/2026 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges. | |
| Aplazada | Crítica (9.3) | 3.2% | — | Dlink Dwr-m961AI | 8/8/2026 | 31/8/2026 | D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges. |