Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 6.2% | — | Dlink Dir-882 Firmware | 9/4/2026 | 17/6/2026 | A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could… | |
| Analizada | Media (6.5) | 3.2% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration parameters (`EmailFrom`, `EmailTo`, `SMTPServerAddress`, `SMTPServerPort`, `AccountName`) in NVRAM… | |
| Analizada | Media (6.5) | 3.2% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later… | |
| Analizada | Alta (7.3) | 3.9% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied `SetSysLogSettings/IPAddress` values in NVRAM via `nvram_safe_set("SysLogRemote_IPAddress", ...)`. These values are… | |
| Analizada | Alta (7.3) | 3.8% | — | Dlink Dir-882 Firmware | 13/11/2025 | 17/6/2026 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are later retrieved in the… | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 18% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via… | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8) | 2.1% | — | Dlink Dir-882 FirmwareDlink Dir-878 Firmware | 17/10/2024 | 17/6/2026 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | |
| Analizada | Alta (8.8) | 1.3% | — | Dlink Dir-882 Firmware | 21/2/2024 | 17/6/2026 | Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/. | |
| Modificada | Media (5.3) | 18% | — | Dlink Dir-825acg1 FirmwareDlink Dir-841 FirmwareDlink Dir-1260 FirmwareDlink Dir-822 Firmware+40 | 19/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882,… | |
| Modificada | Alta (7.5) | 0.91% | — | Dlink Dir-882 Firmware | 31/3/2023 | 17/6/2026 | An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-882 1.30. A specially crafted network request can lead to the disclosure of sensitive information. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-882 Firmware | 22/11/2022 | 17/6/2026 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dlink Dir-882 Firmware | 22/11/2022 | 17/6/2026 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dlink Dir-882 Firmware | 22/11/2022 | 17/6/2026 | D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. | |
| Modificada | Crítica (9.8) | 3.5% | — | Dlink Dir-882 Firmware | 10/5/2022 | 17/6/2026 | A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload. | |
| Modificada | Crítica (9.8) | 3.5% | — | Dlink Dir-882 Firmware | 10/5/2022 | 17/6/2026 | A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload. | |
| Modificada | Crítica (9.8) | 3.5% | — | Dlink Dir-882 Firmware | 10/5/2022 | 17/6/2026 | A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload. | |
| Modificada | Crítica (9.8) | 5.3% | — | Dlink Dir-882 Firmware | 2/5/2022 | 17/6/2026 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. |