Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.98%—Dlink Dir-868lAI20/9/202622/9/2026
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit…
AnalizadaAlta (8.9)6.7%—Dlink Dir-868l Firmware3/3/202617/6/2026
A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products…
AnalizadaAlta (7.4)3.8%—Dlink Dir-868l B1 FirmwareDlink Dir-860l B1 Firmware14/12/202517/6/2026
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AnalizadaAlta (7.3)7.6%—Dlink Dir-868l Firmware19/11/202517/6/2026
D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command.
AnalizadaCrítica (9.8)7.0%—Dlink Dir-868l Firmware28/8/202517/6/2026
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or…
ModificadaCrítica (9.8)1.4%—Dlink Dir-868l Firmware18/8/202317/6/2026
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.
ModificadaCrítica (9.8)1.4%—Dlink Dir-868l Firmware18/8/202317/6/2026
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the FUN_0000acb4 function.
ModificadaCrítica (9.8)1.4%—Dlink Dir-868l Firmware18/8/202317/6/2026
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.
ModificadaCrítica (9.8)0.90%—Dlink Dir-868l Firmware2/5/202317/6/2026
D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.
ModificadaMedia (5.3)1.8%—D-link Dir-868lw Firmware31/10/20219/7/2026
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
ModificadaAlta (7.5)1.4%—Dlink Dir-868l Firmware4/6/202117/6/2026
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
ModificadaAlta (7.5)2.2%—Dlink Dir-859 FirmwareDlink Dir-822 FirmwareDlink Dir-823 FirmwareDlink Dir-865l Firmware+102/1/202017/6/2026
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
AnalizadaCrítica (9.8)90%⚠ Explotación activaDlink Dir-859 FirmwareDlink Dir-822 FirmwareDlink Dir-823 FirmwareDlink Dir-865l Firmware+1030/12/201917/6/2026
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
ModificadaCrítica (9.8)4.9%—Dlink Dir-868l FirmwareDlink Dir-890l FirmwareDlink Dir-885l FirmwareDlink Dir-895l Firmware+214/10/201917/6/2026
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack:…
ModificadaCrítica (9.8)56%—Dlink Dir-868l B1 FirmwareDlink Dir-817lw A1 Firmware11/10/201917/6/2026
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with AUTHORIZED_GROUP=1%0a to getcfg.php. This could be used…
ModificadaCrítica (9.8)2.7%—Dlink Dir-868l FirmwareDlink Dir-885l FirmwareDlink Dir-895l Firmware9/9/201917/6/2026
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.
ModificadaCrítica (9.8)7.4%—D-link Dir-868l Firmware13/5/201917/6/2026
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking.…
ModificadaCrítica (9.8)13%—D-link Dir-818lw FirmwareD-link Dir-822 FirmwareDlink Dir-822 FirmwareD-link Dir-860l Firmware+313/5/201917/6/2026
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in…
ModificadaAlta (7.5)2.6%—Dlink Dir-817lw FirmwareDlink Dir-816l FirmwareDlink Dir-816 FirmwareDlink Dir-850l Firmware+125/3/201917/6/2026
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?),…
ModificadaCrítica (9.8)80%—Dlink Dir-823 FirmwareDlink Dir-822 FirmwareDlink Dir-818l(w) FirmwareDlink Dir-895l Firmware+513/7/201817/6/2026
Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L,…
ModificadaAlta (8.8)0.84%—Dlink Dir-868l Firmware10/5/201817/6/2026
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.
AnalizadaCrítica (9.8)97%⚠ Explotación activaDlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l FirmwareDlink Dir-880l Firmware6/3/201817/6/2026
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous…
ModificadaMedia (6.1)1.6%—Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l Firmware6/3/201817/6/2026
XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted Treturn parameter to…
ModificadaMedia (6.1)1.6%—Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l Firmware6/3/201817/6/2026
XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to…
ModificadaMedia (6.1)1.6%—Dlink Dir-860l FirmwareDlink Dir-865l FirmwareDlink Dir-868l Firmware6/3/201817/6/2026
XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted deviceid…