Dlink
Dlink Dir-878 Firmware: vulnerabilidades y CVE
Dlink Dir-878 Firmware tiene 39 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses4
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-60676 | Media (6.5) | 3.5% | — | 13 nov 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and… |
| CVE-2025-60674 | Media (6.8) | 0.56% | — | 13 nov 2025 | A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device… |
| CVE-2025-60673 | Media (6.5) | 3.5% | — | 13 nov 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi… |
| CVE-2025-60672 | Media (6.5) | 3.6% | — | 13 nov 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and… |
| CVE-2025-0481 | Media (6.9) | 1.4% | — | 15 ene 2025 | A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information… |
| CVE-2024-48638 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows… |
| CVE-2024-48637 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to… |
| CVE-2024-48636 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to… |
| CVE-2024-48635 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to… |
| CVE-2024-48634 | Alta (8) | 18% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to… |
| CVE-2024-48633 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the… |
| CVE-2024-48632 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings… |
| CVE-2024-48631 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to… |
| CVE-2024-48630 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to… |
| CVE-2024-48629 | Alta (8) | 2.1% | — | 17 oct 2024 | D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows… |
| CVE-2024-0717 | Media (5.3) | 18% | — | 19 ene 2024 | A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825,… |
| CVE-2023-27720 | Crítica (9.8) | 1.4% | — | 9 abr 2023 | D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload. |
| CVE-2023-24800 | Crítica (9.8) | 1.3% | — | 7 abr 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted… |
| CVE-2023-24799 | Crítica (9.8) | 1.1% | — | 7 abr 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted… |
| CVE-2023-24798 | Crítica (9.8) | 1.1% | — | 7 abr 2023 | D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted… |
| CVE-2022-41140 | Alta (8.8) | 1.1% | — | 26 ene 2023 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of multiple D-Link routers. Authentication is not required to exploit this vulnerability. The specific flaw exists… |
| CVE-2022-44801 | Crítica (9.8) | 1.2% | — | 22 nov 2022 | D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. |
| CVE-2022-44202 | Crítica (9.8) | 1.2% | — | 22 nov 2022 | D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. |
| CVE-2022-43184 | Crítica (9.8) | 1.8% | — | 19 oct 2022 | D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi. |
| CVE-2022-1262 | Alta (7.8) | 2.2% | — | 11 abr 2022 | A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root. |
| CVE-2022-26670 | Alta (8.8) | 1.5% | — | 7 abr 2022 | D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system… |
| CVE-2021-44882 | Crítica (9.8) | 4.5% | — | 4 feb 2022 | D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST… |
| CVE-2021-44880 | Crítica (9.8) | 4.0% | — | 4 feb 2022 | D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to… |
| CVE-2021-30072 | Crítica (9.8) | 1.4% | — | 2 abr 2021 | An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication. |
| CVE-2020-8864 | Alta (8.8) | 80% | — | 23 mar 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authentication is not required to exploit… |