Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 12/5/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 11/5/2026 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 5.0% | — | Dlink Dir-816 Firmware | 11/5/2026 | 17/6/2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (8.9) | 1.9% | — | Dlink Dir-816 Firmware | 16/3/2026 | 17/6/2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possible to be carried out… | |
| Analizada | Alta (8.9) | 1.9% | — | Dlink Dir-816 Firmware | 16/3/2026 | 17/6/2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been… | |
| Analizada | Alta (8.9) | 1.9% | — | Dlink Dir-816 Firmware | 16/3/2026 | 17/6/2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is possible. The… | |
| Analizada | Alta (8.9) | 1.9% | — | Dlink Dir-816 Firmware | 16/3/2026 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remotely. The exploit… | |
| Analizada | Media (5.5) | 3.0% | — | Dlink Dir-816 Firmware | 16/3/2026 | 17/6/2026 | A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper access controls. The attack may be initiated remotely. The exploit is publicly available and might be… | |
| Modificada | Alta (8.8) | 0.67% | — | Dlink Dir-816 Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated using sprintf() into… | |
| Analizada | Alta (7.5) | 5.7% | — | Dlink Dir-816 Firmware | 9/10/2025 | 17/6/2026 | D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Crítica (9.8) | 1.0% | — | Dlink Dir-816 Firmware | 30/6/2025 | 5/7/2026 | An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file | |
| Analizada | Crítica (9.3) | 2.6% | — | Dlink Dir-816 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.3) | 2.5% | — | Dlink Dir-816 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument port0_group/port0_remarker/ssid0_group/ssid0_remarker leads to stack-based buffer overflow. The attack can be… | |
| Analizada | Crítica (9.3) | 19% | — | Dlink Dir-816 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The… | |
| Analizada | Crítica (9.3) | 2.5% | — | Dlink Dir-816 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based buffer overflow. The attack may be… | |
| Analizada | Media (6.9) | 7.5% | — | Dlink Dir-816 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 7.7% | — | Dlink Dir-816 Firmware | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.5) | 1.0% | — | Dlink Dir-816 Firmware | 22/4/2025 | 17/6/2026 | D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting. | |
| Analizada | Media (5.1) | 8.7% | — | Dlink Dir-816 Firmware | 17/2/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. The manipulation of the argument SSID leads to cross site scripting. The attack can… | |
| Analizada | Crítica (9.8) | 14% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request. | |
| Analizada | Media (4.3) | 0.54% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request. | |
| Analizada | Media (6.5) | 0.47% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request. | |
| Analizada | Media (5.3) | 0.51% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request. | |
| Analizada | Media (5.3) | 0.51% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request. | |
| Analizada | Media (6.5) | 0.57% | — | Dlink Dir-816 Firmware | 16/1/2025 | 17/6/2026 | An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request. |