Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 19 respecto a la semana anterior
Críticas / altas1451▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.65%—Dlink Dir-825AI24/9/202624/9/2026
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.
AplazadaBaja (2.1)4.4%—Dlink Dir-825mAI31/8/202631/8/2026
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The…
AplazadaAlta (8.6)0.91%—Dlink Dir-825mAI31/8/20261/9/2026
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit…
AplazadaAlta (8.6)0.91%—Dlink Dir-825mAI30/8/202631/8/2026
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now…
AnalizadaAlta (7.4)1.2%—Dlink Dir-825m Firmware28/4/202617/6/2026
A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.4)1.2%—Dlink Dir-825m Firmware28/4/202617/6/2026
A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may…
AnalizadaAlta (7.3)0.74%—Dlink Dir-825 Firmware27/4/202617/6/2026
A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network.…
AnalizadaAlta (7.4)1.1%—Dlink Dir-825 Firmware27/4/202617/6/2026
A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability…
AplazadaAlta (8.6)3.4%—Dlink Dir-825AIDlink Dir-825rAI24/3/202617/6/2026
A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only affects products that…
AnalizadaBaja (2.1)8.3%—Dlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dir-822k FirmwareDlink Dir-825m Firmware18/11/202517/6/2026
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been…
AnalizadaAlta (7.4)3.6%—Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+117/11/202517/6/2026
A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has…
AnalizadaAlta (7.4)0.81%—Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+117/11/202517/6/2026
A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit…
ModificadaAlta (7.4)3.3%—Dlink Dir-825 Firmware18/9/202517/6/2026
A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be…
AnalizadaAlta (7.4)0.97%—Dlink Dir-825 Firmware6/9/202517/6/2026
A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_response.cg of the component httpd. Performing manipulation of the argument ping6_ipaddr results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and…
AnalizadaAlta (7.3)0.93%—Dlink Dir-825 Firmware14/8/202517/6/2026
A vulnerability was identified in D-Link DIR-825 2.10. Affected by this vulnerability is the function get_ping_app_stat of the file ping_response.cgi of the component httpd. The manipulation of the argument ping_ipaddr leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
AnalizadaAlta (8.9)18%—Dlink Dir-825 Firmware9/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in D-Link DIR-825 2.10. This issue affects the function sub_410DDC of the file switch_language.cgi of the component httpd. The manipulation of the argument Language leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit…
AnalizadaAlta (7.4)1.3%—Dlink Dir-825 Firmware20/6/202517/6/2026
A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaAlta (7.4)1.3%—Dlink Dir-825 Firmware20/6/202517/6/2026
A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
AplazadaCrítica (9.8)1.2%—Dlink Dir-825AI27/1/202517/6/2026
DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.
ModificadaMedia (5.3)18%—Dlink Dir-825acg1 FirmwareDlink Dir-841 FirmwareDlink Dir-1260 FirmwareDlink Dir-822 Firmware+4019/1/202417/6/2026
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882,…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the xupnpd service, which listens on TCP port 4044. The issue results from the lack…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Vimeo plugin for the xupnpd service, which listens on TCP port 4044. The issue…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the IVI plugin for the xupnpd service, which listens on TCP port 4044. The issue…
ModificadaAlta (8.8)0.95%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Dreambox plugin for the xupnpd service, which listens on TCP port 4044. The…
ModificadaAlta (8.8)1.9%—Dlink Dir-825/ee FirmwareDlink Dir-825/ac Firmware29/3/202317/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Generic plugin for the xupnpd service, which listens on TCP port 4044. The issue…