Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.45% | — | Dlink Dir-895lAI | 26/9/2026 | 28/9/2026 | A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used. | |
| Aplazada | Alta (8.6) | 0.72% | — | Dlink Dir-895lAI | 8/9/2026 | 11/9/2026 | A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 2.3% | — | Dlink Dir-895lAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Analizada | Crítica (9.8) | 9.7% | — | Dlink Dir-895la1 Firmware | 9/1/2026 | 17/6/2026 | A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP client renews an… | |
| Modificada | Crítica (9.8) | 1.5% | — | Dlink Dir-895l Firmware | 31/7/2023 | 17/6/2026 | Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Alta (7.5) | 1.1% | — | Dlink Dir-895l MFC Firmware | 4/6/2021 | 17/6/2026 | The DLink Router DIR-895L MFC v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data. | |
| Modificada | Alta (7.5) | 2.2% | — | Dlink Dir-859 FirmwareDlink Dir-822 FirmwareDlink Dir-823 FirmwareDlink Dir-865l Firmware+10 | 2/1/2020 | 17/6/2026 | D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php. | |
| Analizada | Crítica (9.8) | 90% | ⚠ Explotación activa | Dlink Dir-859 FirmwareDlink Dir-822 FirmwareDlink Dir-823 FirmwareDlink Dir-865l Firmware+10 | 30/12/2019 | 17/6/2026 | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. | |
| Modificada | Crítica (9.8) | 4.9% | — | Dlink Dir-868l FirmwareDlink Dir-890l FirmwareDlink Dir-885l FirmwareDlink Dir-895l Firmware+2 | 14/10/2019 | 17/6/2026 | Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack:… | |
| Modificada | Crítica (9.8) | 2.7% | — | Dlink Dir-868l FirmwareDlink Dir-885l FirmwareDlink Dir-895l Firmware | 9/9/2019 | 17/6/2026 | SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php. | |
| Modificada | Crítica (9.8) | 80% | — | Dlink Dir-823 FirmwareDlink Dir-822 FirmwareDlink Dir-818l(w) FirmwareDlink Dir-895l Firmware+5 | 13/7/2018 | 17/6/2026 | Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L,… | |
| Modificada | Media (6.5) | 0.45% | — | Dlink Dir-890l FirmwareD-link Dir-885l/r FirmwareD-link Dir-895l/r Firmware | 5/7/2018 | 17/6/2026 | An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices (all hardware revisions). Due to the predictability of the /docs/captcha_(number).jpeg URI, being local to the network,… | |
| Modificada | Crítica (9.8) | 12% | — | Dlink Dir-868l FirmwareDlink Dir-822 FirmwareD-link Dir-880l FirmwareD-link Dir-850l Firmare+6 | 25/8/2016 | 17/6/2026 | Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1… |