Vulnerabilities in D-link

822 results
Vexday analysis

D-Link apresenta footprint mínimo de vulnerabilidades na base com apenas 1 CVE registrado, publicado recentemente (últimos 90 dias), sem exploração ativa confirmada ou classificações críticas. A fraqueza identificada (CWE-266: Permissions, Privileges, and Access Controls) sugere falha em controle de acesso, mas o baixo volume e ausência de ataques ativos mantêm o risco em nível moderado no presente.

CVE-2023-5154MEDIUMD-Link DAR-8000 changelogo.php unrestricted uploadEPSS 15.1%CVE-2025-6898MEDIUMD-Link DI-7300G+ in proxy_client.asp os command injectionEPSS 14.5%CVE-2025-1103HIGHD-Link DIR-823X HTTP POST Request set_wifi_blacklists null pointer dereferenceEPSS 14.1%CVE-2025-5573MEDIUMD-Link DCS-932L setSystemWizard setSystemControl os command injectionEPSS 13.8%CVE-2013-10050HIGHD-Link Devices tools_vct.xgi Authenticated RCEEPSS 13.6%CVE-2025-5571MEDIUMD-Link DCS-932L setSystemAdmin os command injectionEPSS 13.6%CVE-2025-4902MEDIUMD-Link DI-7003GV2 versionupdate.data sub_48F4F0 information disclosureEPSS 13.5%CVE-2020-8862HIGHThis vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2610 Firmware v2.01RC0EPSS 13.3%CVE-2025-3538HIGHD-Link DI-8100 jhttpd auth.asp auth_asp stack-based overflowEPSS 13.2%CVE-2013-10069CRITICALD-Link Devices Unauthenticated RCEEPSS 11.9%CVE-2025-10440MEDIUMD-Link DI-8100/DI-8100G/DI-8200/DI-8200G/DI-8003/DI-8003G jhttpd usb_paswd.asp sub_4621DC os command injectionEPSS 11.8%CVE-2025-10441MEDIUMD-Link DI-8100G/DI-8200G/DI-8003G jhttpd version_upgrade.asp sub_433F7C os command injectionEPSS 11.8%CVE-2026-0732MEDIUMD-Link DI-8200G upgrade_filter.asp command injectionEPSS 11.7%CVE-2025-3785HIGHD-Link DWR-M961 Authorization Interface formStaticDHCP stack-based overflowEPSS 11.4%CVE-2025-14884HIGHD-Link DIR-605 Firmware Update Service command injectionEPSS 11.0%CVE-2025-4544HIGHD-Link DI-8100 jhttpd ddos.asp stack-based overflowEPSS 10.9%CVE-2025-60344HIGHA path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpuEPSS 10.9%CVE-2025-2546MEDIUMD-Link DIR-618/DIR-605L Firewall Service formAdvFirewall access controlEPSS 10.8%CVE-2018-25115CRITICALD-Link DIR-110/412/600/615/645/815 RCE via service.cgiEPSS 10.4%CVE-2025-9745MEDIUMD-Link DI-500WF jhttpd version_upgrade.asp os command injectionEPSS 10.2%