Dlink
Dlink D-view 8: vulnerabilidades y CVE
Dlink D-view 8 tiene 19 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses2
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-23755 | Alta (8.4) | 0.17% | — | 21 ene 2026 | D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its… |
| CVE-2026-23754 | Alta (8.7) | 0.38% | — | 21 ene 2026 | D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data… |
| CVE-2024-5299 | Alta (8.8) | 1.8% | — | 23 may 2024 | D-Link D-View execMonitorScript Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although… |
| CVE-2024-5298 | Alta (8.8) | 1.8% | — | 23 may 2024 | D-Link D-View queryDeviceCustomMonitorResult Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View.… |
| CVE-2024-5297 | Alta (8.8) | 1.9% | — | 23 may 2024 | D-Link D-View executeWmicCmd Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although… |
| CVE-2024-5296 | Crítica (9.8) | 1.1% | — | 23 may 2024 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is… |
| CVE-2023-44414 | Crítica (9.8) | 2.4% | — | 3 may 2024 | D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View.… |
| CVE-2023-44413 | Alta (7.5) | 1.5% | — | 3 may 2024 | D-Link D-View shutdown_coreserver Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of D-Link D-View.… |
| CVE-2023-44412 | Alta (8.2) | 84% | — | 3 may 2024 | D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View.… |
| CVE-2023-44411 | Crítica (9.8) | 2.4% | — | 3 may 2024 | D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View.… |
| CVE-2023-44410 | Alta (8.8) | 1.5% | — | 3 may 2024 | D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of D-Link D-View. Authentication is required… |
| CVE-2023-32169 | Crítica (9.8) | 56% | — | 3 may 2024 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is… |
| CVE-2023-32168 | Alta (8.8) | 1.6% | — | 3 may 2024 | D-Link D-View showUser Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of D-Link D-View. Authentication is required… |
| CVE-2023-32167 | Media (6.5) | 77% | — | 3 may 2024 | D-Link D-View uploadMib Directory Traversal Arbitrary File Creation or Deletion Vulnerability. This vulnerability allows remote attackers to create and delete arbitrary files on affected installations of D-Link D-View.… |
| CVE-2023-32166 | Alta (8.1) | 74% | — | 3 may 2024 | D-Link D-View uploadFile Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of D-Link D-View. Authentication is… |
| CVE-2023-32165 | Crítica (9.8) | 73% | — | 3 may 2024 | D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View.… |
| CVE-2023-32164 | Alta (7.5) | 85% | — | 3 may 2024 | D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View.… |
| CVE-2023-7163 | Crítica (9.8) | 1.7% | — | 28 dic 2023 | A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. This could result in the disclosure of information from other probes,… |
| CVE-2023-5074 | Crítica (9.8) | 70% | — | 20 sept 2023 | Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28 |