Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3041▲ 585 respecto a la semana anterior
Críticas / altas1451▲ 285 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)4.8%—Dlink Dir-615 Firmware8/2/202617/6/2026
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in os command injection. The attack may be initiated remotely. The exploit has been…
AnalizadaAlta (7.3)4.7%—Dlink Dir-615 Firmware8/2/202617/6/2026
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (7.3)5.6%—Dlink Dir-615 Firmware28/1/202617/6/2026
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed…
AnalizadaAlta (7.3)5.1%—Dlink Dir-615 Firmware28/1/202617/6/2026
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only…
AnalizadaAlta (7.3)5.8%—Dlink Dir-615 Firmware27/1/202617/6/2026
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is…
AnalizadaCrítica (10)10%—Dlink Dir-110 FirmwareDlink Dir-412 FirmwareDlink Dir-600 FirmwareDlink Dir-610 Firmware+327/8/202517/6/2026
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input…
AnalizadaAlta (8.6)27%—Dlink Dir-615h Firmware1/8/202516/6/2026
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowing attackers to…
ModificadaAlta (8.7)14%—Dlink Dir-300 FirmwareDlink Dir-615 Firmware1/8/202516/6/2026
An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing attackers with valid credentials to…
ModificadaMedia (5.3)18%—Dlink Dir-825acg1 FirmwareDlink Dir-841 FirmwareDlink Dir-1260 FirmwareDlink Dir-822 Firmware+4019/1/202417/6/2026
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882,…
ModificadaCrítica (9.8)63%—Dlink Dir-615 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-615 T1 FirmwareDlink Dir-615jx10 Firmware23/8/20229/7/2026
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
ModificadaMedia (6.5)1.9%—Dlink Dir-615 Firmware24/9/202117/6/2026
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
ModificadaCrítica (9.8)3.7%—Dlink Dir-615 Firmware6/8/202117/6/2026
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.
ModificadaAlta (8.8)5.8%—Dlink Dir-615 Firmware21/4/202017/6/2026
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
ModificadaAlta (8.8)1.6%—Dlink Dir-615jx10 Firmware2/3/202017/6/2026
fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malformed.
ModificadaAlta (8.8)1.6%—Dlink Dir-615jx10 Firmware2/3/202017/6/2026
fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup webpage parameter when f_radius_ip1 is malformed.
ModificadaMedia (4.8)20%—Dlink Dir-615 Firmware18/12/201917/6/2026
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
ModificadaMedia (6.5)8.9%—Dlink Dir-615 T1 Firmware16/12/201917/6/2026
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
ModificadaCrítica (9.8)1.6%—Dlink Dir-600 B1 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-645 A1 FirmwareDlink Dir-815 A1 Firmware+311/11/201917/6/2026
Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign or /etc/alpha_config/image_sign. This affects DIR-600 B1 V2.01 for WW, DIR-890L A1 v1.03, DIR-615 J1 v100 (for DCN), DIR-645 A1 v1.03, DIR-815 A1 v1.01, DIR-823 A1 v1.01, and DIR-842 C1 v3.00.
ModificadaAlta (8.2)3.0%—Dlink Dir-615 Firmware9/10/201917/6/2026
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
AnalizadaCrítica (9.8)100%⚠ Explotación activaDlink Dir-655 FirmwareDlink Dir-866l FirmwareDlink Dir-652 FirmwareDlink Dhp-1565 Firmware+627/9/201917/6/2026
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection…
ModificadaCrítica (9.8)45%—Dlink Dir-615 Firmware28/8/201817/6/2026
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
ModificadaMedia (6.1)1.2%—Dlink Dir-615 Firmware25/8/201817/6/2026
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
ModificadaMedia (6.1)1.2%—Dlink Dir-615 Firmware25/8/201817/6/2026
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
ModificadaAlta (7.2)2.7%—D-link Dir-615 Firmware26/4/201817/6/2026
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
ModificadaMedia (4.8)3.4%—D-link Dir-615 T1 Firmware18/4/201817/6/2026
D-Link DIR-615 T1 devices allow XSS via the Add User feature.