Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.4) | 0.91% | — | Dlink Dir-878AI | 14/9/2026 | 15/9/2026 | A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the attack is possible. | |
| Aplazada | Crítica (9.4) | 0.91% | — | Dlink Dir-878AI | 14/9/2026 | 15/9/2026 | A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched remotely. | |
| Modificada | Media (6.5) | 3.5% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell commands executed via system(). An… | |
| Modificada | Media (6.8) | 0.56% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack… | |
| Modificada | Media (6.5) | 3.5% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands executed via… | |
| Modificada | Media (6.5) | 3.6% | — | Dlink Dir-878 Firmware | 13/11/2025 | 5/7/2026 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construct system commands… | |
| Analizada | Media (6.9) | 1.4% | — | Dlink Dir-878 Firmware | 15/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 18% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via… | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Modificada | Media (5.3) | 18% | — | Dlink Dir-825acg1 FirmwareDlink Dir-841 FirmwareDlink Dir-1260 FirmwareDlink Dir-822 Firmware+40 | 19/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882,… | |
| Modificada | Crítica (9.8) | 1.4% | — | Dlink Dir-878 Firmware | 9/4/2023 | 17/6/2026 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-878 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dlink Dir-878 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dlink Dir-878 Firmware | 7/4/2023 | 17/6/2026 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. | |
| Modificada | Alta (8.8) | 1.1% | — | Dlink Dir-882-us FirmwareDlink Dir-867 FirmwareDlink Dir-878 Firmware | 26/1/2023 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the lighttpd service, which listens on TCP port 80 by default. The issue results from the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Dlink Dir-878 Firmware | 22/11/2022 | 17/6/2026 | D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dlink Dir-878 Firmware | 22/11/2022 | 17/6/2026 | D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. |