Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)1.1%—Dlink Dir-816 A2 Firmware1/5/202517/6/2026
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary commands via shell.
ModificadaCrítica (9.8)38%—Dlink Dir-816 A2 Firmware26/1/202417/6/2026
A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setDeviceSettings of the component Web Interface. The manipulation of the argument statuscheckpppoeuser leads to os command injection. The attack can…
ModificadaCrítica (9.8)13%—Dlink Dir-816 A2 Firmware21/9/202317/6/2026
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.
ModificadaCrítica (9.8)13%—Dlink Dir-816 A2 Firmware21/9/202317/6/2026
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.
ModificadaCrítica (9.8)1.3%—Dlink Dir-816 A2 Firmware21/9/202317/6/2026
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.
ModificadaCrítica (9.8)13%—Dlink Dir-816 A2 Firmware21/9/202317/6/2026
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.
ModificadaCrítica (9.8)1.1%—Dlink Dir-816 A2 Firmware21/9/202317/6/2026
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.
ModificadaCrítica (9.8)4.1%—D-link Dir-816 A2 Firmware20/12/201817/6/2026
D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.
ModificadaCrítica (9.8)3.7%—Dlink Dir-816 A2 Firmware15/9/201817/6/2026
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter.
ModificadaCrítica (9.8)1.9%—Dlink Dir-816 A2 Firmware15/9/201817/6/2026
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address.
ModificadaCrítica (9.8)7.3%—Dlink Dir-816 A2 Firmware15/9/201817/6/2026
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter.
ModificadaCrítica (9.8)1.9%—Dlink Dir-816 A2 Firmware15/9/201817/6/2026
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address.
ModificadaCrítica (9.8)7.4%—Dlink Dir-816 A2 Firmware15/9/201817/6/2026
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked.
ModificadaCrítica (9.8)4.1%—Dlink Dir-816 A2 Firmware15/9/201817/6/2026
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters.
ModificadaCrítica (9.8)6.4%—D-link Dir-816 A2 Firmware13/5/201817/6/2026
Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthenticated remote attackers to execute arbitrary code via a request with a long HTTP Host header.