Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Total 1765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-65731 1 Dlink 2 Dir-605l, Dir-605l Firmware 2026-06-17 N/A 6.8 MEDIUM
An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacker with physical access to the UART pins to execute arbitrary commands due to presence of root terminal access on a serial interface without proper access control.
CVE-2025-63932 1 Dlink 2 Dir-868l, Dir-868l Firmware 2026-06-17 N/A 7.3 HIGH
D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command.
CVE-2025-61577 1 Dlink 2 Dir-816, Dir-816 Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-60854 1 Dlink 2 R15, R15 Firmware 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
CVE-2025-60701 1 Dlink 2 Dir-882, Dir-882 Firmware 2026-06-17 N/A 6.5 MEDIUM
A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration parameters (`EmailFrom`, `EmailTo`, `SMTPServerAddress`, `SMTPServerPort`, `AccountName`) in NVRAM via `nvram_safe_set`. These values are later retrieved in the `sub_448FDC` function of `rc` using `nvram_safe_get` and concatenated into shell commands executed via `twsystem()` without sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
CVE-2025-60700 1 Dlink 2 Dir-882, Dir-882 Firmware 2026-06-17 N/A 6.5 MEDIUM
A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These values are later retrieved in the `DMZ_run` function of `librcm.so` using `nvram_safe_get` and concatenated into `iptables` shell commands executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
CVE-2025-60698 1 Dlink 2 Dir-882, Dir-882 Firmware 2026-06-17 N/A 7.3 HIGH
A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied `SetSysLogSettings/IPAddress` values in NVRAM via `nvram_safe_set("SysLogRemote_IPAddress", ...)`. These values are later retrieved in the `sub_448DCC` function of `rc` using `nvram_safe_get` and concatenated into a shell command executed via `twsystem()` without any sanitization. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
CVE-2025-60697 1 Dlink 2 Dir-882, Dir-882 Firmware 2026-06-17 N/A 7.3 HIGH
A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are later retrieved in the `start_DDNS_ipv4` function of `rc` using `nvram_safe_get` and concatenated into DDNS shell commands executed via `twsystem()` without proper sanitization. Partial string comparison is performed but is insufficient to prevent command injection. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the device through specially crafted HTTP requests to the router's web interface.
CVE-2025-60572 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvNetwork.
CVE-2025-60571 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600LAx FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetQoS.
CVE-2025-60570 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLogDnsquery.
CVE-2025-60569 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetRoute.
CVE-2025-60568 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formAdvFirewall.
CVE-2025-60566 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetMACFilter.
CVE-2025-60565 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSchedule.
CVE-2025-60564 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetLog.
CVE-2025-60563 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetPortTr.
CVE-2025-60562 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formWlSiteSurvey.
CVE-2025-60561 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEmail.
CVE-2025-60559 1 Dlink 2 Dir-600l, Dir-600l Firmware 2026-06-17 N/A 7.5 HIGH
D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetDomainFilter.