D-Link Vulnerabilities and Affected Products
Vulnerabilities associated with DAR-8000-10.
Products
Clear product- DNS-32059 vulnerabilities
- DAP-262254 vulnerabilities
- DNS-32550 vulnerabilities
- DNS-340L49 vulnerabilities
- DNS-320LW48 vulnerabilities
- DNS-320L47 vulnerabilities
- DNS-327L47 vulnerabilities
- DIR-605L46 vulnerabilities
- DNR-322L45 vulnerabilities
- DNS-34545 vulnerabilities
- DNR-202L44 vulnerabilities
- DNR-32644 vulnerabilities
- DNS-1100-444 vulnerabilities
- DNS-12044 vulnerabilities
- DNS-1200-0544 vulnerabilities
- DNS-1550-0444 vulnerabilities
- DNS-315L44 vulnerabilities
- DNS-32144 vulnerabilities
- DNS-32344 vulnerabilities
- DNS-32644 vulnerabilities
- DNS-34344 vulnerabilities
- DNS-726-444 vulnerabilities
- DAP-132537 vulnerabilities
- DIR-619L37 vulnerabilities
- DIR-823X32 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-4699MEDIUM | D-Link DAR-8000-10 importhtml.php deserialization** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-263747. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early … CWE-502May 10, 2024 | CVSS5.3v4.0 | EPSS6.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4711MEDIUM | D-Link DAR-8000-10 decodmail.php os command injectionA vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230819. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. VDB-238574 is the identifier assigned to this vulnerabil… CWE-78Sep 1, 2023 | CVSS5.0v3.1 | EPSS5.77% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4542MEDIUM | D-Link DAR-8000-10 sys1.php os command injectionA vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238047. NOTE: The vendor was contacted early about this disclosure but did not respond in any… | CVSS6.3v3.1 | EPSS87.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |