Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.91% | — | Dlink Dir-645AI | 9/4/2026 | 24/7/2026 | A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that… | |
| Analizada | Baja (2.1) | 4.6% | — | Dlink Dir-645 Firmware | 18/9/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerability only affects… | |
| Analizada | Crítica (10) | 10% | — | Dlink Dir-110 FirmwareDlink Dir-412 FirmwareDlink Dir-600 FirmwareDlink Dir-610 Firmware+3 | 27/8/2025 | 17/6/2026 | Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input… | |
| Analizada | Baja (2.1) | 4.3% | — | Dlink Dir-645 Firmware | 8/7/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-645 up to 1.05B01 and classified as critical. This issue affects the function ssdpcgi_main of the file /htdocs/cgibin of the component ssdpcgi. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 1.5% | — | Dlink Dir-645 Firmware | 31/7/2023 | 17/6/2026 | Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Crítica (9.8) | 9.5% | — | Dlink Dir-645 Firmware | 17/1/2023 | 17/6/2026 | D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main function. | |
| Modificada | Crítica (9.8) | 5.8% | — | Dlink Dir-645 Firmware | 27/6/2022 | 17/6/2026 | D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi. | |
| Modificada | Crítica (9.8) | 3.2% | — | Dlink Dir-645 Firmware | 31/3/2022 | 17/6/2026 | D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size. | |
| Modificada | Media (6.1) | 0.99% | — | Dlink Dir-803 FirmwareDlink Dir-816l FirmwareDlink Dir-645 FirmwareDlink Dir-815 Firmware+2 | 19/9/2020 | 17/6/2026 | webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and… | |
| Modificada | Crítica (9.8) | 1.6% | — | Dlink Dir-600 B1 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-645 A1 FirmwareDlink Dir-815 A1 Firmware+3 | 11/11/2019 | 17/6/2026 | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00. | |
| Modificada | Crítica (9.8) | 24% | — | Dlink Dir-300 FirmwareDlink Dir-600 FirmwareDlink Dir-645 FirmwareDlink Dir-845 Firmware+1 | 11/6/2019 | 17/6/2026 | An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST… | |
| Modificada | Alta (10) | 5.2% | — | Dlink Dir-645 Firmware | 23/2/2015 | 17/6/2026 | Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary code via a long string in a GetDeviceSettings action to the HNAP interface. | |
| Analizada | Alta (8.8) | 97% | ⚠ Explotación activa | Dlink Dir-645 Firmware | 23/2/2015 | 17/6/2026 | The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. | |
| Modificada | Media (4.3) | 28% | — | Dlink Dir-645 FirmwareDlink Dir-645 | 7/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid parameter to parentalcontrols/bind.php, (2) RESULT parameter to info.php, or (3) receiver parameter to bsc_sms_send.php. |