Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)24%—Dlink Dir-816 Firmware31/8/202217/6/2026
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
ModificadaCrítica (9.8)22%—Dlink Dir-816 Firmware31/8/202217/6/2026
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
ModificadaCrítica (9.8)22%—Dlink Dir-816 Firmware22/8/202217/6/2026
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.
ModificadaAlta (7.5)1.3%—Dlink Dir-816 Firmware22/8/202217/6/2026
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
ModificadaCrítica (9.8)3.8%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.
ModificadaCrítica (9.8)3.8%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.
ModificadaCrítica (9.8)3.8%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.
ModificadaCrítica (9.8)4.0%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.
ModificadaCrítica (9.8)4.0%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.
ModificadaCrítica (9.8)17%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.
ModificadaCrítica (9.8)4.0%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.
ModificadaCrítica (9.8)6.3%—Dlink Dir-816 Firmware10/5/202217/6/2026
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
ModificadaCrítica (9.8)2.2%—Dlink Dir-816 Firmware24/3/202217/6/2026
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.
ModificadaCrítica (9.8)8.6%—Dlink Dir-816 Firmware24/8/202117/6/2026
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
ModificadaCrítica (9.8)5.1%—Dlink Dir-816 Firmware24/8/202117/6/2026
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
ModificadaCrítica (9.8)25%—Dlink Dir-816 Firmware14/4/202117/6/2026
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.
ModificadaCrítica (9.8)3.5%—Dlink Dir-816 Firmware14/4/202117/6/2026
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.
ModificadaCrítica (9.8)4.9%—Dlink Dir-816 Firmware30/3/202117/6/2026
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.
ModificadaAlta (7.5)2.6%💥 PoCDlink Dir-817lw FirmwareDlink Dir-816l FirmwareDlink Dir-816 FirmwareDlink Dir-850l Firmware+125/3/201917/6/2026
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?),…
ModificadaAlta (7.5)1.7%—Dlink Dir-816 Firmware25/3/201917/6/2026
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.
ModificadaCrítica (9.8)1.5%—Dlink Dir-816 Firmware25/3/201917/6/2026
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.
ModificadaCrítica (9.8)2.5%—Dlink Dir-816 Firmware25/3/201917/6/2026
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /goform/SystemCommand to execute a system command without authentication.
ModificadaCrítica (9.8)1.9%—Dlink Dir-816 Firmware25/3/201917/6/2026
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setSysAdm to edit the web or system account without authentication.
Orbitaley — Vulnerabilidades