Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 3.3% | — | Dlink Dwr-m920AI | 14/9/2026 | 14/9/2026 | A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (2.1) | 1.0% | — | Dlink Dwr-m920AI | 5/6/2026 | 17/6/2026 | A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 3.1% | — | Dlink Dwr-m920 Firmware | 5/6/2026 | 17/6/2026 | A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 4.2% | — | Dlink Dwr-m920 Firmware | 5/6/2026 | 23/7/2026 | A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 5/10/2026 | A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2.1) | 4.1% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 5/10/2026 | A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly… | |
| Analizada | Baja (2.1) | 4.1% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 30/9/2026 | A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the file /boafrm/formLtefotaUpgradeFibocom. This manipulation of the argument fota_url causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the… | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 5/10/2026 | A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42261C of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be exploited. | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dwr-m920 Firmware | 29/12/2025 | 5/10/2026 | A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /boafrm/formDefRoute. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.4) | 0.70% | — | Dlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (7.4) | 0.76% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released… | |
| Analizada | Alta (7.4) | 0.76% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Analizada | Alta (7.4) | 0.76% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed… | |
| Analizada | Alta (7.4) | 0.79% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.4) | 0.74% | — | Dlink Dir-822k FirmwareDlink Dwr-m920 Firmware | 23/11/2025 | 17/6/2026 | A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 8.3% | — | Dlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dir-822k FirmwareDlink Dir-825m Firmware | 18/11/2025 | 17/6/2026 | A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Alta (7.4) | 3.6% | — | Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+1 | 17/11/2025 | 17/6/2026 | A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has… | |
| Analizada | Alta (7.4) | 0.81% | — | Dlink Dir-825m FirmwareDlink Dwr-m920 FirmwareDlink Dwr-m921 FirmwareDlink Dwr-m961 Firmware+1 | 17/11/2025 | 17/6/2026 | A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit… |