« Volver al listado

Dlink

Dlink Dir-865l Firmware: vulnerabilidades y CVE

Dlink Dir-865l Firmware tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses0
Críticas3
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-17621Crítica (9.8)90%⚠ Explotación activa30 dic 2019
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE…
CVE-2018-6530Crítica (9.8)97%⚠ Explotación activa6 mar 2018
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2020-25786Media (6.1)0.99%—19 sept 2020
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.…
CVE-2020-13787Alta (7.5)0.90%—3 jun 2020
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
CVE-2020-13786Alta (8.8)0.69%—3 jun 2020
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
CVE-2020-13785Alta (7.5)0.59%—3 jun 2020
D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.
CVE-2020-13784Alta (7.5)1.3%—3 jun 2020
D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
CVE-2020-13783Alta (7.5)0.90%—3 jun 2020
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
CVE-2020-13782Alta (8.8)27%—3 jun 2020
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
CVE-2019-20213Alta (7.5)2.2%—2 ene 2020
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
CVE-2019-17621Crítica (9.8)90%⚠ Explotación activa30 dic 2019
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE…
CVE-2013-4857Crítica (9.8)1.6%—25 oct 2019
D-Link DIR-865L has PHP File Inclusion in the router xml file.
CVE-2013-4856Media (6.5)0.87%—25 oct 2019
D-Link DIR-865L has Information Disclosure.
CVE-2013-4855Alta (8.8)1.5%—25 oct 2019
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.
CVE-2018-6530Crítica (9.8)97%⚠ Explotación activa6 mar 2018
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L…
CVE-2018-6529Media (6.1)1.6%—6 mar 2018
XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04…
CVE-2018-6528Media (6.1)1.6%—6 mar 2018
XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04…
CVE-2018-6527Media (6.1)1.6%—6 mar 2018
XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Dlink