Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 11% | — | Dlink Dsr-150AIDlink Dsr-150nAIDlink Dsr-250nAI | 21/10/2025 | 17/6/2026 | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access to files outside of the intended directory,… | |
| Analizada | Alta (8.8) | 3.6% | — | Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+2 | 28/1/2025 | 17/6/2026 | Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution. | |
| Modificada | Crítica (9.8) | 15% | — | Dlink Dsr-250 FirmwareDlink Dsr-1000n Firmware | 2/2/2021 | 17/6/2026 | The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution. | |
| Modificada | Alta (8.8) | 2.3% | — | Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+6 | 15/12/2020 | 17/6/2026 | An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests. | |
| Modificada | Alta (8.8) | 1.3% | — | Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+6 | 15/12/2020 | 17/6/2026 | An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root. | |
| Modificada | Alta (8.8) | 2.1% | — | Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+6 | 15/12/2020 | 17/6/2026 | A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17. | |
| Modificada | Media (5.5) | 17% | — | Dlink Dsr-250n Firmware | 8/10/2020 | 17/6/2026 | An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes. | |
| Modificada | Alta (7.2) | 3.4% | — | Dlink Dsr-250n Firmware | 19/2/2020 | 16/6/2026 | D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password. | |
| Modificada | Crítica (9.8) | 9.8% | — | Dlink Dsr-150 FirmwareDlink Dsr-150n FirmwareDlink Dsr-250 FirmwareDlink Dsr-250n Firmware+4 | 11/2/2020 | 16/6/2026 | Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the… | |
| Modificada | Alta (7.2) | 2.0% | — | Dlink Dsr-250n Firmware | 25/1/2020 | 16/6/2026 | D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account. | |
| Modificada | Media (4.9) | 0.66% | — | Dlink Dsr-150 FirmwareDlink Dsr-150Dlink Dsr-250 FirmwareDlink Dsr-250+11 | 19/12/2013 | 17/6/2026 | D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive information by reading… | |
| Modificada | Alta (7.8) | 1.9% | — | Dlink Dsr-500 FirmwareDlink Dsr-500Dlink Dsr-150n FirmwareDlink Dsr-150n+11 | 19/12/2013 | 17/6/2026 | D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 have a hardcoded account of username gkJ9232xXyruTRmY, which makes it easier for remote attackers to obtain… | |
| Modificada | Alta (10) | 6.5% | — | Dlink Dsr-500 FirmwareDlink Dsr-500Dlink Dsr-150n FirmwareDlink Dsr-150n+11 | 19/12/2013 | 16/6/2026 | The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allows remote attackers to execute arbitrary commands via… |