Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.22%—Dlink Di-8100gAI24/8/202629/9/2026
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
AnalizadaAlta (7.5)0.33%—Dlink Di-8100 FirmwareDlink Di-8100g FirmwareDlink Di-8004w FirmwareDlink Di-8003g Firmware+58/4/202625/7/2026
D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key,…
AplazadaBaja (2.1)12%—Dlink Di-8100gAIDlink Di-8200gAIDlink Di-8003gAI15/9/202517/6/2026
A vulnerability was found in D-Link DI-8100G, DI-8200G and DI-8003G 17.12.20A1/19.12.10A1. Affected by this issue is the function sub_433F7C of the file version_upgrade.asp of the component jhttpd. The manipulation of the argument path results in os command injection. The attack may be launched remotely. The exploit…
AplazadaBaja (2.1)12%—Dlink Di-8100AIDlink Di-8100gAIDlink Di-8200AIDlink Di-8200gAI+215/9/202517/6/2026
A vulnerability has been found in D-Link DI-8100, DI-8100G, DI-8200, DI-8200G, DI-8003 and DI-8003G 16.07.26A1/17.12.20A1/19.12.10A1. Affected by this vulnerability is the function sub_4621DC of the file usb_paswd.asp of the component jhttpd. The manipulation of the argument hname leads to os command injection. The…
AnalizadaCrítica (9.8)20%—Dlink Di-8100g Firmware20/5/202517/6/2026
D-link DI-8100 16.07.26A1 is vulnerable to Command Injection. An attacker can exploit this vulnerability by crafting specific HTTP requests, triggering the command execution flaw and gaining the highest privilege shell access to the firmware system.
AnalizadaAlta (8.6)8.2%—Dlink Di-8100g Firmware18/5/202517/6/2026
A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been declared as critical. This vulnerability affects the function ctxz_asp of the file /ctxz.asp of the component Connection Limit Page. The manipulation of the argument def/defTcp/defUdp/defIcmp/defOther leads to stack-based buffer overflow. The attack…
AnalizadaCrítica (9.8)3.1%—Dlink Di-8100g Firmware6/9/202417/6/2026
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
AnalizadaCrítica (9.8)2.9%—Dlink Di-8100g Firmware6/9/202417/6/2026
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
Orbitaley — Vulnerabilidades