Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)4.8%—Dlink Dir-615 Firmware8/2/202617/6/2026
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/ submask/ gw results in os command injection. The attack may be initiated remotely. The exploit has been…
AnalizadaAlta (7.3)4.7%—Dlink Dir-615 Firmware8/2/202617/6/2026
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (7.3)5.6%—Dlink Dir-615 Firmware28/1/202617/6/2026
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed…
AnalizadaAlta (7.3)5.1%—Dlink Dir-615 Firmware28/1/202617/6/2026
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only…
AnalizadaAlta (7.3)5.8%—Dlink Dir-615 Firmware27/1/202617/6/2026
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is…
AnalizadaCrítica (10)10%—Dlink Dir-110 FirmwareDlink Dir-412 FirmwareDlink Dir-600 FirmwareDlink Dir-610 Firmware+327/8/202517/6/2026
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication. The flaw stems from improper input…
ModificadaAlta (8.7)14%—Dlink Dir-300 FirmwareDlink Dir-615 Firmware1/8/202516/6/2026
An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing attackers with valid credentials to…
ModificadaMedia (5.3)18%—Dlink Dir-825acg1 FirmwareDlink Dir-841 FirmwareDlink Dir-1260 FirmwareDlink Dir-822 Firmware+4019/1/202417/6/2026
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882,…
ModificadaCrítica (9.8)63%—Dlink Dir-615 FirmwareDlink Dir-615 J1 FirmwareDlink Dir-615 T1 FirmwareDlink Dir-615jx10 Firmware23/8/20229/7/2026
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
ModificadaMedia (6.5)1.9%—Dlink Dir-615 Firmware24/9/202117/6/2026
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
ModificadaCrítica (9.8)3.7%—Dlink Dir-615 Firmware6/8/202117/6/2026
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.
ModificadaAlta (8.8)5.8%—Dlink Dir-615 Firmware21/4/202017/6/2026
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
ModificadaMedia (4.8)20%—Dlink Dir-615 Firmware18/12/201917/6/2026
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
ModificadaAlta (8.2)3.0%—Dlink Dir-615 Firmware9/10/201917/6/2026
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
AnalizadaCrítica (9.8)100%⚠ Explotación activaDlink Dir-655 FirmwareDlink Dir-866l FirmwareDlink Dir-652 FirmwareDlink Dhp-1565 Firmware+627/9/201917/6/2026
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection…
ModificadaCrítica (9.8)45%—Dlink Dir-615 Firmware28/8/201817/6/2026
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
ModificadaMedia (6.1)1.2%—Dlink Dir-615 Firmware25/8/201817/6/2026
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
ModificadaMedia (6.1)1.2%—Dlink Dir-615 Firmware25/8/201817/6/2026
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
ModificadaAlta (7.2)2.7%—D-link Dir-615 Firmware26/4/201817/6/2026
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
ModificadaCrítica (9.8)5.1%—D-link Dir-615 Firmware11/6/201717/6/2026
D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.
ModificadaAlta (8.8)3.0%—D-link Dir-615 Firmware4/4/201717/6/2026
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID…
AnalizadaCrítica (9.8)100%⚠ Explotación activaDlink Dir-905l FirmwareDlink Dir-605l FirmwareDlink Dir-600l FirmwareDlink Dir-619l Firmware+221/5/201517/6/2026
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.