Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 3.6% | — | Dlink Dir-860l Firmware | 15/8/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.5) | 0.67% | — | Dlink Dir-860l Firmware | 17/12/2024 | 17/6/2026 | A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request. | |
| Modificada | Crítica (9.8) | 16% | — | Dlink Dir-860l Firmware | 19/8/2024 | 17/6/2026 | In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands. | |
| Analizada | Crítica (9.8) | 0.78% | — | Dlink Dir-860l Firmware | 30/7/2024 | 17/6/2026 | In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands. | |
| Modificada | Media (6.1) | 0.99% | — | Dlink Dir-803 FirmwareDlink Dir-816l FirmwareDlink Dir-645 FirmwareDlink Dir-815 Firmware+2 | 19/9/2020 | 17/6/2026 | webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and… | |
| Modificada | Crítica (9.8) | 13% | — | D-link Dir-818lw FirmwareD-link Dir-822 FirmwareDlink Dir-822 FirmwareD-link Dir-860l Firmware+3 | 13/5/2019 | 17/6/2026 | D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in… | |
| Modificada | Crítica (9.8) | 6.7% | — | Dlink Dir-818lw FirmwareDlink Dir-860l Firmware | 2/1/2019 | 17/6/2026 | On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-6530. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa | Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l FirmwareDlink Dir-880l Firmware | 6/3/2018 | 17/6/2026 | OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous… | |
| Modificada | Media (6.1) | 1.6% | — | Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l Firmware | 6/3/2018 | 17/6/2026 | XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted Treturn parameter to… | |
| Modificada | Media (6.1) | 1.6% | — | Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l Firmware | 6/3/2018 | 17/6/2026 | XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to… | |
| Modificada | Media (6.1) | 1.6% | — | Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l Firmware | 6/3/2018 | 17/6/2026 | XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted deviceid… |