D-Link Vulnerabilities and Affected Products
Vulnerabilities associated with DIR-825 R1 Devices.
Products
Clear product- DNS-32059 vulnerabilities
- DAP-262254 vulnerabilities
- DNS-32550 vulnerabilities
- DNS-340L49 vulnerabilities
- DNS-320LW48 vulnerabilities
- DNS-320L47 vulnerabilities
- DNS-327L47 vulnerabilities
- DIR-605L46 vulnerabilities
- DNR-322L45 vulnerabilities
- DNS-34545 vulnerabilities
- DNR-202L44 vulnerabilities
- DNR-32644 vulnerabilities
- DNS-1100-444 vulnerabilities
- DNS-12044 vulnerabilities
- DNS-1200-0544 vulnerabilities
- DNS-1550-0444 vulnerabilities
- DNS-315L44 vulnerabilities
- DNS-32144 vulnerabilities
- DNS-32344 vulnerabilities
- DNS-32644 vulnerabilities
- DNS-34344 vulnerabilities
- DNS-726-444 vulnerabilities
- DAP-132537 vulnerabilities
- DIR-619L37 vulnerabilities
- DIR-823X32 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-46442CRITICAL | D-Link DIR-825 R1 Devices Improper AuthenticationIn the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization. Apr 27, 2022 | CVSS9.8v3.1 | EPSS55.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-29557CRITICAL | D-Link DIR-825 R1 Devices Buffer Overflow VulnerabilityAn issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution. | CVSS9.8v3.1 | EPSS54.3% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-10215HIGH | D-Link DIR-825 R1 Devices Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affected. CWE-78Mar 7, 2020 | CVSS8.8v3.1 | EPSS5.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |