Vulnerabilidades em D-Link

822 resultados
Análise Vexday

Com 777 CVEs catalogadas e 57 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da D-Link apresenta um ritmo de descoberta que exige monitoramento contínuo. A taxa de exploração ativa está em linha com a média geral do catálogo, mas o destaque crítico é CVE-2024-3273, que possui EPSS máximo de 1.0 — indicando probabilidade extremamente alta de exploração ativa —, e deve ser tratada como prioridade absoluta de mitigação. A presença de 80 CVEs com PoC pública, combinada com 56 falhas de severidade crítica, amplia significativamente a superfície de ataque disponível para agentes mal-intencionados. O tipo de falha mais frequente, CWE-121 (stack-based buffer overflow), é historicamente associado à execução remota de código, o que reforça a urgência de aplicar correções e segmentar dispositivos D-Link expostos à rede.

CVE-2022-43646HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 1.0%CVE-2022-43645HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 1.0%CVE-2022-43644HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 1.0%CVE-2022-43647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 1.0%CVE-2023-41230HIGHD-Link DIR-3040 HTTP Request Processing Referer Stack-Based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.0%CVE-2025-11339HIGHD-Link DI-7100G C1 jhttpd hi_block.asp sub_4BD4F8 buffer overflowEPSS 1.0%CVE-2025-6334HIGHD-Link DIR-867 Query String strncpy stack-based overflowEPSS 1.0%CVE-2023-35724HIGHD-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass VulnerabilityEPSS 0.9%CVE-2023-50204HIGHD-Link G416 flupl pythonapp Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50215HIGHD-Link G416 nodered gz File Handling Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50203HIGHD-Link G416 nodered chmod Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50214HIGHD-Link G416 nodered tar File Handling Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-2055MEDIUMD-Link DIR-605L/DIR-619L DHCP Client Information information disclosureEPSS 0.9%CVE-2025-10034HIGHD-Link DIR-825 httpd ping6_response.cg get_ping6_app_stat buffer overflowEPSS 0.9%CVE-2026-2056MEDIUMD-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information disclosureEPSS 0.9%CVE-2026-2054MEDIUMD-Link DIR-605L/DIR-619L Wifi Setting information disclosureEPSS 0.9%CVE-2025-4859MEDIUMD-Link DAP-2695 MAC Bypass Settings Page adv_macbypass.php cross site scriptingEPSS 0.9%CVE-2023-32138HIGHD-Link DAP-1360 webproc Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-8949HIGHD-Link DIR-825 httpd ping_response.cgi get_ping_app_stat stack-based overflowEPSS 0.9%CVE-2022-43648HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 1.20B03 routers.EPSS 0.9%