« Volver al listado

Dlink

Dlink Dir-820l Firmware: vulnerabilidades y CVE

Dlink Dir-820l Firmware tiene 15 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 9 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses1
Críticas9
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-25280Crítica (9.8)98%⚠ Explotación activa16 mar 2023
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
CVE-2022-26258Crítica (9.8)92%⚠ Explotación activa28 mar 2022
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVE-2021-45382Crítica (9.8)98%⚠ Explotación activa17 feb 2022
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L,…
CVE-2015-1187Crítica (9.8)83%⚠ Explotación activa21 sept 2017
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-52079Alta (8.8)0.54%—21 oct 2025
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
CVE-2024-51186Alta (8)0.86%—11 nov 2024
D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.
CVE-2024-48150Crítica (9.8)0.71%—14 oct 2024
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
CVE-2023-44809Crítica (9.8)0.85%—16 oct 2023
D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
CVE-2023-44808Crítica (9.8)0.85%—16 oct 2023
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.
CVE-2023-44807Crítica (9.8)1.1%—6 oct 2023
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.
CVE-2023-25281Alta (7.5)1.1%—16 mar 2023
A stack overflow vulnerability exists in pingV4Msg component in D-Link DIR820LA1_FW105B03, allows attackers to cause a denial of service via the nextPage parameter to ping.ccp.
CVE-2023-25280Crítica (9.8)98%⚠ Explotación activa16 mar 2023
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
CVE-2023-25282Media (6.5)1.0%—15 mar 2023
A heap overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the config.log_to_syslog and log_opt_dropPackets parameters to mydlink_api.ccp.
CVE-2023-25279Crítica (9.8)31%—13 mar 2023
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.
CVE-2023-25283Alta (7.5)1.2%—13 mar 2023
A stack overflow vulnerability in D-Link DIR820LA1_FW106B02 allows attackers to cause a denial of service via the reserveDHCP_HostName_1.1.1.0 parameter to lan.asp.
CVE-2022-34973Alta (7.5)15%—3 ago 2022
D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.
CVE-2022-26258Crítica (9.8)92%⚠ Explotación activa28 mar 2022
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVE-2021-45382Crítica (9.8)98%⚠ Explotación activa17 feb 2022
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L,…
CVE-2015-1187Crítica (9.8)83%⚠ Explotación activa21 sept 2017
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter5
  2. T1190 Exploit Public-Facing Application5
  3. T1210 Exploitation of Remote Services2
  4. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Dlink