Search

Find a vulnerability

Search criteria

    180 vulnerabilities by dlink

    CVE-2026-23755 (GCVE-0-2026-23755)

    Vulnerability from nvd – Published: 2026-01-21 18:02 – Updated: 2026-05-14 02:09
    VLAI
    Title
    D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path
    Summary
    D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-22 15:11 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    References
    Impacted products
    Vendor Product Version
    D-Link D-View 8 Affected: 0 , ≤ 2.0.1.107 (custom)
        cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23755",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-22T15:11:07.575974Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-22T16:50:59.815Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "D-View 8",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.1.107",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.0.1.107",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise."
                }
              ],
              "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427 Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-14T02:09:24.354Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10471"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-dview-8-installer-dll-preloading-via-uncontrolled-search-path"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later.\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-23755",
        "datePublished": "2026-01-21T18:02:30.160Z",
        "dateReserved": "2026-01-15T18:42:20.938Z",
        "dateUpdated": "2026-05-14T02:09:24.354Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23754 (GCVE-0-2026-23754)

    Vulnerability from nvd – Published: 2026-01-21 18:02 – Updated: 2026-05-14 02:09
    VLAI
    Title
    D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover
    Summary
    D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-22 15:11 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    References
    Impacted products
    Vendor Product Version
    D-Link D-View 8 Affected: 0 , ≤ 2.0.1.107 (custom)
        cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23754",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-22T15:11:04.543748Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-22T16:50:54.833Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "D-View 8",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.1.107",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.0.1.107",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system."
                }
              ],
              "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-14T02:09:23.656Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10471"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-dview-8-idor-allows-credential-disclosure-and-account-takeover"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later.\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-23754",
        "datePublished": "2026-01-21T18:02:45.878Z",
        "dateReserved": "2026-01-15T18:42:20.938Z",
        "dateUpdated": "2026-05-14T02:09:23.656Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34255 (GCVE-0-2025-34255)

    Vulnerability from nvd – Published: 2025-10-16 18:52 – Updated: 2026-05-25 23:41
    VLAI
    Title
    D-Link Nuclias Connect <= v1.3.1.4 Forgot Password Account Enumeration
    Summary
    D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server. NOTE: D-Link states that a fix is under development.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-17 14:29 UTC
    CWE
    • CWE-204 - Observable Response Discrepancy
    Impacted products
    Vendor Product Version
    D-Link Nuclias Connect Affected: 0 , ≤ 1.3.1.4 (custom)
        cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34255",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-17T14:29:11.316268Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-17T14:29:17.095Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "web interface"
              ],
              "product": "Nuclias Connect",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "1.3.1.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.1.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams from Pellera Technologies"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link Nuclias Connect firmware versions \u0026lt;= 1.3.1.4 contain an observable response discrepancy vulnerability.\u0026nbsp;The application\u0027s \u0027Forgot Password\u0027 endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server.\u0026nbsp;NOTE: D-Link states that a fix is under development.\u003cbr\u003e"
                }
              ],
              "value": "D-Link Nuclias Connect firmware versions \u003c= 1.3.1.4 contain an observable response discrepancy vulnerability.\u00a0The application\u0027s \u0027Forgot Password\u0027 endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server.\u00a0NOTE: D-Link states that a fix is under development."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-575",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-575 Account Footprinting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-204",
                  "description": "CWE-204 Observable Response Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-25T23:41:31.628Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-nuclias-connect-forgot-password-account-enumeration"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/en/for-business/nuclias/nuclias-connect"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link Nuclias Connect \u003c= v1.3.1.4 Forgot Password Account Enumeration",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34255",
        "datePublished": "2025-10-16T18:52:59.964Z",
        "dateReserved": "2025-04-15T19:15:22.578Z",
        "dateUpdated": "2026-05-25T23:41:31.628Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34254 (GCVE-0-2025-34254)

    Vulnerability from nvd – Published: 2025-10-16 18:52 – Updated: 2026-05-25 23:41
    VLAI
    Title
    D-Link Nuclias Connect <= v1.3.1.4 Login Account Enumeration
    Summary
    D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-17 14:29 UTC
    CWE
    • CWE-204 - Observable Response Discrepancy
    Impacted products
    Vendor Product Version
    D-Link Nuclias Connect Affected: 0 , ≤ 1.3.1.4 (custom)
        cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34254",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-17T14:29:43.264857Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-17T14:29:49.920Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "web interface"
              ],
              "product": "Nuclias Connect",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "1.3.1.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.1.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams from Pellera Technologies"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link Nuclias Connect firmware versions \u0026lt;= 1.3.1.4 contain an observable response discrepancy vulnerability.\u0026nbsp;The application\u0027s \u0027Login\u0027 endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server.\u0026nbsp;NOTE: D-Link states that a fix is under development.\u003cbr\u003e"
                }
              ],
              "value": "D-Link Nuclias Connect firmware versions \u003c= 1.3.1.4 contain an observable response discrepancy vulnerability.\u00a0The application\u0027s \u0027Login\u0027 endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server.\u00a0NOTE: D-Link states that a fix is under development."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-575",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-575 Account Footprinting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-204",
                  "description": "CWE-204 Observable Response Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-25T23:41:30.851Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-nuclias-connect-login-account-enumeration"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/en/for-business/nuclias/nuclias-connect"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link Nuclias Connect \u003c= v1.3.1.4 Login Account Enumeration",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34254",
        "datePublished": "2025-10-16T18:52:08.435Z",
        "dateReserved": "2025-04-15T19:15:22.578Z",
        "dateUpdated": "2026-05-25T23:41:30.851Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34253 (GCVE-0-2025-34253)

    Vulnerability from nvd – Published: 2025-10-16 18:53 – Updated: 2026-05-14 02:07
    VLAI
    Title
    D-Link Nuclias Connect <= v1.3.1.4 Stored Cross-Site Scripting (XSS)
    Summary
    D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-17 14:28 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
    Impacted products
    Vendor Product Version
    D-Link Nuclias Connect Affected: 0 , < 1.3.1.4 (custom)
        cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34253",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-17T14:28:34.087394Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-17T14:28:40.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Nuclias Connect",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThan": "1.3.1.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.1.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams from Pellera Technologies"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link Nuclias Connect firmware versions \u0026lt;= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the \u0027Network\u0027 field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.\u003cbr\u003e"
                }
              ],
              "value": "D-Link Nuclias Connect firmware versions \u003c= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the \u0027Network\u0027 field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-592",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-592 Stored XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-14T02:07:58.251Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-nuclias-connect-stored-xss"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/en/for-business/nuclias/nuclias-connect"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link Nuclias Connect \u003c= v1.3.1.4 Stored Cross-Site Scripting (XSS)",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34253",
        "datePublished": "2025-10-16T18:53:49.731Z",
        "dateReserved": "2025-04-15T19:15:22.578Z",
        "dateUpdated": "2026-05-14T02:07:58.251Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-28726 (GCVE-0-2024-28726)

    Vulnerability from nvd – Published: 2024-11-12 00:00 – Updated: 2024-11-13 15:50
    VLAI
    Summary
    An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-13 15:50 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink dwr-2000m_firmware Affected: 1.34
        cpe:2.3:o:dlink:dwr-2000m_firmware:1.34:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dwr-2000m_firmware:1.34:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dwr-2000m_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.34"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28726",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-13T15:50:17.319668Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-13T15:50:22.582Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-12T22:11:43.887Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/Mrnmap/mrnmap-cve"
            },
            {
              "url": "https://github.com/Mrnmap/mrnmap-cve/blob/main/CVE-2024-28726"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-28726",
        "datePublished": "2024-11-12T00:00:00.000Z",
        "dateReserved": "2024-03-08T00:00:00.000Z",
        "dateUpdated": "2024-11-13T15:50:22.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44415 (GCVE-0-2024-44415)

    Vulnerability from nvd – Published: 2024-10-11 00:00 – Updated: 2024-10-15 20:43
    VLAI
    Summary
    A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 20:40 UTC
    CWE
    • n/a
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    dlink di-8200_firmware Affected: 16.07.26a1
        cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-8200_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "16.07.26a1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44415",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T20:40:17.426033Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-120",
                    "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T20:43:03.154Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-11T16:52:53.406Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/DI-8200/Dlink%20DI-8200.md"
            },
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/DI-8200/CVE-2024-44415"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44415",
        "datePublished": "2024-10-11T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-10-15T20:43:03.154Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44413 (GCVE-0-2024-44413)

    Vulnerability from nvd – Published: 2024-10-11 00:00 – Updated: 2024-10-15 20:46
    VLAI
    Summary
    A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 20:45 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-8200_firmware Affected: 16.07.26a1
        cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-8200_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "16.07.26a1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44413",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T20:45:51.048046Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T20:46:45.226Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-11T16:43:04.303Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/di-8300/di-8200.md"
            },
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/di-8300/CVE-2024-44413"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44413",
        "datePublished": "2024-10-11T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-10-15T20:46:45.226Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9566 (GCVE-0-2024-9566)

    Vulnerability from nvd – Published: 2024-10-07 13:00 – Updated: 2024-10-07 13:25 Unsupported When Assigned
    VLAI
    Title
    D-Link DIR-619L B1 formDeviceReboot buffer overflow
    Summary
    A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-07 13:22 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.279460 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.279460 signaturepermissions-required
    https://vuldb.com/?submit.414541 third-party-advisory
    https://github.com/abcdefg-png/IoT-vulnerable/blo… exploit
    https://www.dlink.com/ product
    Impacted products
    Vendor Product Version
    D-Link DIR-619L B1 Affected: 2.06
    Create a notification for this product.
    d-link dir-619l_b1 Affected: 2.06
        cpe:2.3:h:d-link:dir-619l_b1:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:d-link:dir-619l_b1:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dir-619l_b1",
                "vendor": "d-link",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.06"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9566",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-07T13:22:53.741353Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-07T13:25:20.194Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "DIR-619L B1",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.06"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "yhryhryhr_miemie (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."
            },
            {
              "lang": "de",
              "value": "In D-Link DIR-619L B1 2.06 wurde eine Schwachstelle entdeckt. Sie wurde als kritisch eingestuft. Es geht um die Funktion formDeviceReboot der Datei /goform/formDeviceReboot. Mittels dem Manipulieren des Arguments next_page mit unbekannten Daten kann eine buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 9,
                "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-120",
                  "description": "Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-07T13:00:07.587Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-279460 | D-Link DIR-619L B1 formDeviceReboot buffer overflow",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.279460"
            },
            {
              "name": "VDB-279460 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.279460"
            },
            {
              "name": "Submit #414541 | D-Link DIR-619L B1 2.06 Buffer Overflow",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.414541"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formDeviceReboot.md"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-10-07T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-10-07T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-10-07T08:25:15.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "D-Link DIR-619L B1 formDeviceReboot buffer overflow"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-9566",
        "datePublished": "2024-10-07T13:00:07.587Z",
        "dateReserved": "2024-10-07T06:19:48.194Z",
        "dateUpdated": "2024-10-07T13:25:20.194Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44335 (GCVE-0-2024-44335)

    Vulnerability from nvd – Published: 2024-09-09 00:00 – Updated: 2024-09-09 19:14
    VLAI
    Summary
    D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 19:04 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-7003g_firmware Affected: 19.12.24a1
        cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7003gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200gv2_firmware Affected: 24.04.18e1
        cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7200g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7400g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7400g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003g_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "19.12.24a1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18e1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7400g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7400g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44335",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T19:04:46.219645Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T19:14:19.577Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T17:14:07.099Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.dlink.com/en/security-bulletin/"
            },
            {
              "url": "https://gist.github.com/Swind1er/029fb2a9dab916f926fab40cc059223f"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44335",
        "datePublished": "2024-09-09T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-09-09T19:14:19.577Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44334 (GCVE-0-2024-44334)

    Vulnerability from nvd – Published: 2024-09-09 00:00 – Updated: 2024-09-09 19:28
    VLAI
    Summary
    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 19:17 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-7003g_firmware Affected: 19.12.24a1
        cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7003gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200gv2_firmware Affected: 24.04.18e1
        cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7200g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7400g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7400g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003g_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "19.12.24a1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18e1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7400g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7400g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44334",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T19:17:38.614552Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T19:28:56.670Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T17:12:33.888Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.dlink.com/en/security-bulletin/"
            },
            {
              "url": "https://gist.github.com/Swind1er/563789899a7a4b9c261045a15efea952"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44334",
        "datePublished": "2024-09-09T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-09-09T19:28:56.670Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44333 (GCVE-0-2024-44333)

    Vulnerability from nvd – Published: 2024-09-09 00:00 – Updated: 2024-09-09 20:43
    VLAI
    Summary
    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 20:35 UTC
    CWE
    • n/a
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-7300g\+v2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7300g\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7400g\+v2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7400g\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7003gv2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7003gv2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100g\+v2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7100g\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100gv2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7100gv2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200gv2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7200gv2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7300g\\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7300g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7400g\\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7400g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003gv2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100g\\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100gv2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200gv2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44333",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T20:35:42.751054Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-78",
                    "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T20:43:23.400Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T17:04:20.996Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.dlink.com/en/security-bulletin/"
            },
            {
              "url": "https://gist.github.com/Swind1er/c8656b32058e28e64f92d100c92ca12c"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44333",
        "datePublished": "2024-09-09T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-09-09T20:43:23.400Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-43032 (GCVE-0-2024-43032)

    Vulnerability from nvd – Published: 2024-08-23 00:00 – Updated: 2024-08-23 17:50
    VLAI
    Summary
    autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-23 16:12 UTC
    CWE
    • n/a
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    dlink autman Affected: 2.9.6
        cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "autman",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.9.6"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "PHYSICAL",
                  "availabilityImpact": "LOW",
                  "baseScore": 4.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43032",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-23T16:12:41.442922Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-23T16:28:18.342Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "autMan v2.9.6 allows attackers to bypass authentication via a crafted web request."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-23T17:50:20.482Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/hdbjlizhe/fanli/releases/tag/2.9.6"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-43032",
        "datePublished": "2024-08-23T00:00:00.000Z",
        "dateReserved": "2024-08-05T00:00:00.000Z",
        "dateUpdated": "2024-08-23T17:50:20.482Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-43031 (GCVE-0-2024-43031)

    Vulnerability from nvd – Published: 2024-08-23 00:00 – Updated: 2026-07-05 00:43
    VLAI
    Summary
    autMan v2.9.6 was discovered to contain an access control issue.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-23 16:29 UTC
    CWE
    • n/a
    • CWE-284 - Improper Access Control
    • CWE-121 - Stack-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    dlink autman Affected: 2.9.6
        cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "autman",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.9.6"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "PHYSICAL",
                  "availabilityImpact": "LOW",
                  "baseScore": 4.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43031",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-23T16:29:29.475108Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-284",
                    "description": "CWE-284 Improper Access Control",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-23T16:32:50.258Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "autMan v2.9.6 was discovered to contain an access control issue."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-05T00:43:40.965Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/hdbjlizhe/fanli"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-43031",
        "datePublished": "2024-08-23T00:00:00.000Z",
        "dateReserved": "2024-08-05T00:00:00.000Z",
        "dateUpdated": "2026-07-05T00:43:40.965Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-7922 (GCVE-0-2024-7922)

    Vulnerability from nvd – Published: 2024-08-19 15:00 – Updated: 2024-08-19 18:23 Unsupported When Assigned
    VLAI
    Title
    D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection
    Summary
    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 18:05 UTC
    CWE
    Impacted products
    Vendor Product Version
    D-Link DNS-120 Affected: 20240814
    Create a notification for this product.
    D-Link DNR-202L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-315L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-320 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-320L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-320LW Affected: 20240814
    Create a notification for this product.
    D-Link DNS-321 Affected: 20240814
    Create a notification for this product.
    D-Link DNR-322L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-323 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-325 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-326 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-327L Affected: 20240814
    Create a notification for this product.
    D-Link DNR-326 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-340L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-343 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-345 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-726-4 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-1100-4 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-1200-05 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-1550-04 Affected: 20240814
    Create a notification for this product.
    dlink dns-120_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-120_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dnr-202l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dnr-202l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-315l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-315l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-320_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-320_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-320l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-320l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-320lw_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-320lw_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-321_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-321_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dnr-322l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dnr-322l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-323_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-323_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-325_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-325_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-326_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-326_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-327l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-327l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dnr-326_firmware Affected: 20240814
        cpe:2.3:o:dlink:dnr-326_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-340l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-340l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-343_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-343_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-345_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-345_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-726-4_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-726-4_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-1100-4_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-1100-4_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-1200-05_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-1200-05_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-1550-04_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-1550-04_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-120_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-120_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dnr-202l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dnr-202l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-315l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-315l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-320_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-320_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-320l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-320l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-320lw_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-320lw_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-321_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-321_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dnr-322l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dnr-322l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-323_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-323_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-325_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-325_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-326_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-326_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-327l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-327l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dnr-326_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dnr-326_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-340l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-340l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-343_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-343_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-345_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-345_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-726-4_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-726-4_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-1100-4_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-1100-4_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-1200-05_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-1200-05_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-1550-04_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-1550-04_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7922",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T18:05:19.786796Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T18:23:40.353Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "DNS-120",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNR-202L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-315L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-320",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-320L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-320LW",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-321",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNR-322L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-323",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-325",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-326",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-327L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNR-326",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-340L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-343",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-345",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-726-4",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-1100-4",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-1200-05",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-1550-04",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "BuaaI0TTeam (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 bis 20240814 gefunden. Sie wurde als kritisch eingestuft. Betroffen davon ist die Funktion cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist der Datei /cgi-bin/myMusic.cgi. Durch das Beeinflussen mit unbekannten Daten kann eine command injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-19T15:00:06.847Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-275108 | D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.275108"
            },
            {
              "name": "VDB-275108 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.275108"
            },
            {
              "name": "Submit #391669 | D-Link DNS 320/320L/321/323/325/327L Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.391669"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_create_playlist.md"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_tracks_list.md"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-08-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-08-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-08-19T11:49:33.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-7922",
        "datePublished": "2024-08-19T15:00:06.847Z",
        "dateReserved": "2024-08-19T09:43:35.228Z",
        "dateUpdated": "2024-08-19T18:23:40.353Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-23754 (GCVE-0-2026-23754)

    Vulnerability from cvelistv5 – Published: 2026-01-21 18:02 – Updated: 2026-05-14 02:09
    VLAI
    Title
    D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover
    Summary
    D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-22 15:11 UTC
    CWE
    • CWE-639 - Authorization Bypass Through User-Controlled Key
    References
    Impacted products
    Vendor Product Version
    D-Link D-View 8 Affected: 0 , ≤ 2.0.1.107 (custom)
        cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23754",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-22T15:11:04.543748Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-22T16:50:54.833Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "D-View 8",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.1.107",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.0.1.107",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system."
                }
              ],
              "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-639",
                  "description": "CWE-639 Authorization Bypass Through User-Controlled Key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-14T02:09:23.656Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10471"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-dview-8-idor-allows-credential-disclosure-and-account-takeover"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later.\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-23754",
        "datePublished": "2026-01-21T18:02:45.878Z",
        "dateReserved": "2026-01-15T18:42:20.938Z",
        "dateUpdated": "2026-05-14T02:09:23.656Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-23755 (GCVE-0-2026-23755)

    Vulnerability from cvelistv5 – Published: 2026-01-21 18:02 – Updated: 2026-05-14 02:09
    VLAI
    Title
    D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path
    Summary
    D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-01-22 15:11 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    References
    Impacted products
    Vendor Product Version
    D-Link D-View 8 Affected: 0 , ≤ 2.0.1.107 (custom)
        cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-23755",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-01-22T15:11:07.575974Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-01-22T16:50:59.815Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "D-View 8",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "2.0.1.107",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:*",
                      "versionEndIncluding": "2.0.1.107",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise."
                }
              ],
              "value": "D-Link D-View 8 versions 2.0.1.107 and below contain an uncontrolled search path vulnerability in the installer. When executed with elevated privileges via UAC, the installer attempts to load version.dll from its execution directory, allowing DLL preloading. An attacker can supply a malicious version.dll alongside the legitimate installer so that, when a victim runs the installer and approves the UAC prompt, attacker-controlled code executes with administrator privileges. This can lead to full system compromise."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427 Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-14T02:09:24.354Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10471"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-dview-8-installer-dll-preloading-via-uncontrolled-search-path"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later.\u003cbr\u003e"
                }
              ],
              "value": "Upgrade to D-Link D-View 8 version 2.0.5.109 Beta or later."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path",
          "x_generator": {
            "engine": "Vulnogram 0.5.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-23755",
        "datePublished": "2026-01-21T18:02:30.160Z",
        "dateReserved": "2026-01-15T18:42:20.938Z",
        "dateUpdated": "2026-05-14T02:09:24.354Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34253 (GCVE-0-2025-34253)

    Vulnerability from cvelistv5 – Published: 2025-10-16 18:53 – Updated: 2026-05-14 02:07
    VLAI
    Title
    D-Link Nuclias Connect <= v1.3.1.4 Stored Cross-Site Scripting (XSS)
    Summary
    D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-17 14:28 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
    Impacted products
    Vendor Product Version
    D-Link Nuclias Connect Affected: 0 , < 1.3.1.4 (custom)
        cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34253",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-17T14:28:34.087394Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-17T14:28:40.054Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Nuclias Connect",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThan": "1.3.1.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.1.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams from Pellera Technologies"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link Nuclias Connect firmware versions \u0026lt;= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the \u0027Network\u0027 field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.\u003cbr\u003e"
                }
              ],
              "value": "D-Link Nuclias Connect firmware versions \u003c= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the \u0027Network\u0027 field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-592",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-592 Stored XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or \u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-14T02:07:58.251Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-nuclias-connect-stored-xss"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/en/for-business/nuclias/nuclias-connect"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link Nuclias Connect \u003c= v1.3.1.4 Stored Cross-Site Scripting (XSS)",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34253",
        "datePublished": "2025-10-16T18:53:49.731Z",
        "dateReserved": "2025-04-15T19:15:22.578Z",
        "dateUpdated": "2026-05-14T02:07:58.251Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34255 (GCVE-0-2025-34255)

    Vulnerability from cvelistv5 – Published: 2025-10-16 18:52 – Updated: 2026-05-25 23:41
    VLAI
    Title
    D-Link Nuclias Connect <= v1.3.1.4 Forgot Password Account Enumeration
    Summary
    D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server. NOTE: D-Link states that a fix is under development.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-17 14:29 UTC
    CWE
    • CWE-204 - Observable Response Discrepancy
    Impacted products
    Vendor Product Version
    D-Link Nuclias Connect Affected: 0 , ≤ 1.3.1.4 (custom)
        cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34255",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-17T14:29:11.316268Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-17T14:29:17.095Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "web interface"
              ],
              "product": "Nuclias Connect",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "1.3.1.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.1.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams from Pellera Technologies"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link Nuclias Connect firmware versions \u0026lt;= 1.3.1.4 contain an observable response discrepancy vulnerability.\u0026nbsp;The application\u0027s \u0027Forgot Password\u0027 endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server.\u0026nbsp;NOTE: D-Link states that a fix is under development.\u003cbr\u003e"
                }
              ],
              "value": "D-Link Nuclias Connect firmware versions \u003c= 1.3.1.4 contain an observable response discrepancy vulnerability.\u00a0The application\u0027s \u0027Forgot Password\u0027 endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server.\u00a0NOTE: D-Link states that a fix is under development."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-575",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-575 Account Footprinting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-204",
                  "description": "CWE-204 Observable Response Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-25T23:41:31.628Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-nuclias-connect-forgot-password-account-enumeration"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/en/for-business/nuclias/nuclias-connect"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link Nuclias Connect \u003c= v1.3.1.4 Forgot Password Account Enumeration",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34255",
        "datePublished": "2025-10-16T18:52:59.964Z",
        "dateReserved": "2025-04-15T19:15:22.578Z",
        "dateUpdated": "2026-05-25T23:41:31.628Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-34254 (GCVE-0-2025-34254)

    Vulnerability from cvelistv5 – Published: 2025-10-16 18:52 – Updated: 2026-05-25 23:41
    VLAI
    Title
    D-Link Nuclias Connect <= v1.3.1.4 Login Account Enumeration
    Summary
    D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-10-17 14:29 UTC
    CWE
    • CWE-204 - Observable Response Discrepancy
    Impacted products
    Vendor Product Version
    D-Link Nuclias Connect Affected: 0 , ≤ 1.3.1.4 (custom)
        cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-34254",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-10-17T14:29:43.264857Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-17T14:29:49.920Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "web interface"
              ],
              "product": "Nuclias Connect",
              "vendor": "D-Link",
              "versions": [
                {
                  "lessThanOrEqual": "1.3.1.4",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:dlink:nuclias_connect:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "1.3.1.4",
                      "versionStartIncluding": "0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ],
              "operator": "OR"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Alex Williams from Pellera Technologies"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "D-Link Nuclias Connect firmware versions \u0026lt;= 1.3.1.4 contain an observable response discrepancy vulnerability.\u0026nbsp;The application\u0027s \u0027Login\u0027 endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server.\u0026nbsp;NOTE: D-Link states that a fix is under development.\u003cbr\u003e"
                }
              ],
              "value": "D-Link Nuclias Connect firmware versions \u003c= 1.3.1.4 contain an observable response discrepancy vulnerability.\u00a0The application\u0027s \u0027Login\u0027 endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server.\u00a0NOTE: D-Link states that a fix is under development."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-575",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-575 Account Footprinting"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-204",
                  "description": "CWE-204 Observable Response Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-25T23:41:30.851Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/dlink-nuclias-connect-login-account-enumeration"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/en/for-business/nuclias/nuclias-connect"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10472"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "D-Link Nuclias Connect \u003c= v1.3.1.4 Login Account Enumeration",
          "x_generator": {
            "engine": "vulncheck"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2025-34254",
        "datePublished": "2025-10-16T18:52:08.435Z",
        "dateReserved": "2025-04-15T19:15:22.578Z",
        "dateUpdated": "2026-05-25T23:41:30.851Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-28726 (GCVE-0-2024-28726)

    Vulnerability from cvelistv5 – Published: 2024-11-12 00:00 – Updated: 2024-11-13 15:50
    VLAI
    Summary
    An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-13 15:50 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink dwr-2000m_firmware Affected: 1.34
        cpe:2.3:o:dlink:dwr-2000m_firmware:1.34:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dwr-2000m_firmware:1.34:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dwr-2000m_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.34"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28726",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-13T15:50:17.319668Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-13T15:50:22.582Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-12T22:11:43.887Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/Mrnmap/mrnmap-cve"
            },
            {
              "url": "https://github.com/Mrnmap/mrnmap-cve/blob/main/CVE-2024-28726"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-28726",
        "datePublished": "2024-11-12T00:00:00.000Z",
        "dateReserved": "2024-03-08T00:00:00.000Z",
        "dateUpdated": "2024-11-13T15:50:22.582Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44415 (GCVE-0-2024-44415)

    Vulnerability from cvelistv5 – Published: 2024-10-11 00:00 – Updated: 2024-10-15 20:43
    VLAI
    Summary
    A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 20:40 UTC
    CWE
    • n/a
    • CWE-120 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
    Impacted products
    Vendor Product Version
    dlink di-8200_firmware Affected: 16.07.26a1
        cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-8200_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "16.07.26a1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 6.5,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44415",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T20:40:17.426033Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-120",
                    "description": "CWE-120 Buffer Copy without Checking Size of Input (\u0027Classic Buffer Overflow\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T20:43:03.154Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy function is executed without checking the length of the string, leading to a buffer overflow."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-11T16:52:53.406Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/DI-8200/Dlink%20DI-8200.md"
            },
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/DI-8200/CVE-2024-44415"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44415",
        "datePublished": "2024-10-11T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-10-15T20:43:03.154Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44413 (GCVE-0-2024-44413)

    Vulnerability from cvelistv5 – Published: 2024-10-11 00:00 – Updated: 2024-10-15 20:46
    VLAI
    Summary
    A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-15 20:45 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-8200_firmware Affected: 16.07.26a1
        cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-8200_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-8200_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "16.07.26a1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44413",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-15T20:45:51.048046Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-15T20:46:45.226Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injection."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-11T16:43:04.303Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/di-8300/di-8200.md"
            },
            {
              "url": "https://github.com/IotChan/cve/blob/main/dlink/di-8300/CVE-2024-44413"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44413",
        "datePublished": "2024-10-11T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-10-15T20:46:45.226Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9566 (GCVE-0-2024-9566)

    Vulnerability from cvelistv5 – Published: 2024-10-07 13:00 – Updated: 2024-10-07 13:25 Unsupported When Assigned
    VLAI
    Title
    D-Link DIR-619L B1 formDeviceReboot buffer overflow
    Summary
    A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-07 13:22 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.279460 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.279460 signaturepermissions-required
    https://vuldb.com/?submit.414541 third-party-advisory
    https://github.com/abcdefg-png/IoT-vulnerable/blo… exploit
    https://www.dlink.com/ product
    Impacted products
    Vendor Product Version
    D-Link DIR-619L B1 Affected: 2.06
    Create a notification for this product.
    d-link dir-619l_b1 Affected: 2.06
        cpe:2.3:h:d-link:dir-619l_b1:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:h:d-link:dir-619l_b1:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dir-619l_b1",
                "vendor": "d-link",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.06"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9566",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-07T13:22:53.741353Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-07T13:25:20.194Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "DIR-619L B1",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.06"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "yhryhryhr_miemie (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of the argument next_page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used."
            },
            {
              "lang": "de",
              "value": "In D-Link DIR-619L B1 2.06 wurde eine Schwachstelle entdeckt. Sie wurde als kritisch eingestuft. Es geht um die Funktion formDeviceReboot der Datei /goform/formDeviceReboot. Mittels dem Manipulieren des Arguments next_page mit unbekannten Daten kann eine buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 9,
                "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-120",
                  "description": "Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-10-07T13:00:07.587Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-279460 | D-Link DIR-619L B1 formDeviceReboot buffer overflow",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.279460"
            },
            {
              "name": "VDB-279460 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.279460"
            },
            {
              "name": "Submit #414541 | D-Link DIR-619L B1 2.06 Buffer Overflow",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.414541"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/D-Link/DIR-619L/formDeviceReboot.md"
            },
            {
              "tags": [
                "product"
              ],
              "url": "https://www.dlink.com/"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-10-07T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-10-07T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-10-07T08:25:15.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "D-Link DIR-619L B1 formDeviceReboot buffer overflow"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-9566",
        "datePublished": "2024-10-07T13:00:07.587Z",
        "dateReserved": "2024-10-07T06:19:48.194Z",
        "dateUpdated": "2024-10-07T13:25:20.194Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44333 (GCVE-0-2024-44333)

    Vulnerability from cvelistv5 – Published: 2024-09-09 00:00 – Updated: 2024-09-09 20:43
    VLAI
    Summary
    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 20:35 UTC
    CWE
    • n/a
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-7300g\+v2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7300g\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7400g\+v2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7400g\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7003gv2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7003gv2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100g\+v2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7100g\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100gv2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7100gv2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200gv2_firmware Affected: 24.04.18D1
        cpe:2.3:o:dlink:di-7200gv2_firmware:24.04.18d1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7300g\\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7300g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7400g\\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7400g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003gv2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100g\\+v2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100gv2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200gv2_firmware:24.04.18d1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18D1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44333",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T20:35:42.751054Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-78",
                    "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T20:43:23.400Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T17:04:20.996Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.dlink.com/en/security-bulletin/"
            },
            {
              "url": "https://gist.github.com/Swind1er/c8656b32058e28e64f92d100c92ca12c"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44333",
        "datePublished": "2024-09-09T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-09-09T20:43:23.400Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44335 (GCVE-0-2024-44335)

    Vulnerability from cvelistv5 – Published: 2024-09-09 00:00 – Updated: 2024-09-09 19:14
    VLAI
    Summary
    D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 19:04 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-7003g_firmware Affected: 19.12.24a1
        cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7003gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200gv2_firmware Affected: 24.04.18e1
        cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7200g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7400g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7400g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003g_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "19.12.24a1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18e1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7400g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7400g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44335",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T19:04:46.219645Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T19:14:19.577Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T17:14:07.099Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.dlink.com/en/security-bulletin/"
            },
            {
              "url": "https://gist.github.com/Swind1er/029fb2a9dab916f926fab40cc059223f"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44335",
        "datePublished": "2024-09-09T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-09-09T19:14:19.577Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-44334 (GCVE-0-2024-44334)

    Vulnerability from cvelistv5 – Published: 2024-09-09 00:00 – Updated: 2024-09-09 19:28
    VLAI
    Summary
    D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 19:17 UTC
    CWE
    • n/a
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    dlink di-7003g_firmware Affected: 19.12.24a1
        cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7003gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7100gv2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200gv2_firmware Affected: 24.04.18e1
        cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7200g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7200g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink di-7400g\+v2_firmware Affected: 24.04.18d1
        cpe:2.3:o:dlink:di-7400g\+v2_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003g_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003g_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "19.12.24a1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7003gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7003gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7100gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7100gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200gv2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200gv2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18e1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7200g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7200g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:di-7400g\\+v2_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "di-7400g\\+v2_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "24.04.18d1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "ADJACENT_NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 8.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-44334",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T19:17:38.614552Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-77",
                    "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T19:28:56.670Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T17:12:33.888Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://www.dlink.com/en/security-bulletin/"
            },
            {
              "url": "https://gist.github.com/Swind1er/563789899a7a4b9c261045a15efea952"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-44334",
        "datePublished": "2024-09-09T00:00:00.000Z",
        "dateReserved": "2024-08-21T00:00:00.000Z",
        "dateUpdated": "2024-09-09T19:28:56.670Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-43031 (GCVE-0-2024-43031)

    Vulnerability from cvelistv5 – Published: 2024-08-23 00:00 – Updated: 2026-07-05 00:43
    VLAI
    Summary
    autMan v2.9.6 was discovered to contain an access control issue.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-23 16:29 UTC
    CWE
    • n/a
    • CWE-284 - Improper Access Control
    • CWE-121 - Stack-based Buffer Overflow
    References
    Impacted products
    Vendor Product Version
    dlink autman Affected: 2.9.6
        cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "autman",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.9.6"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "PHYSICAL",
                  "availabilityImpact": "LOW",
                  "baseScore": 4.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43031",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-23T16:29:29.475108Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-284",
                    "description": "CWE-284 Improper Access Control",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              },
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-23T16:32:50.258Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "autMan v2.9.6 was discovered to contain an access control issue."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-05T00:43:40.965Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/hdbjlizhe/fanli"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-43031",
        "datePublished": "2024-08-23T00:00:00.000Z",
        "dateReserved": "2024-08-05T00:00:00.000Z",
        "dateUpdated": "2026-07-05T00:43:40.965Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-43032 (GCVE-0-2024-43032)

    Vulnerability from cvelistv5 – Published: 2024-08-23 00:00 – Updated: 2024-08-23 17:50
    VLAI
    Summary
    autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-23 16:12 UTC
    CWE
    • n/a
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    dlink autman Affected: 2.9.6
        cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:dlink:autman:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "autman",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.9.6"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "PHYSICAL",
                  "availabilityImpact": "LOW",
                  "baseScore": 4.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-43032",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-23T16:12:41.442922Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-23T16:28:18.342Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "autMan v2.9.6 allows attackers to bypass authentication via a crafted web request."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-23T17:50:20.482Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/hdbjlizhe/fanli/releases/tag/2.9.6"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-43032",
        "datePublished": "2024-08-23T00:00:00.000Z",
        "dateReserved": "2024-08-05T00:00:00.000Z",
        "dateUpdated": "2024-08-23T17:50:20.482Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-7922 (GCVE-0-2024-7922)

    Vulnerability from cvelistv5 – Published: 2024-08-19 15:00 – Updated: 2024-08-19 18:23 Unsupported When Assigned
    VLAI
    Title
    D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection
    Summary
    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-19 18:05 UTC
    CWE
    Impacted products
    Vendor Product Version
    D-Link DNS-120 Affected: 20240814
    Create a notification for this product.
    D-Link DNR-202L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-315L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-320 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-320L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-320LW Affected: 20240814
    Create a notification for this product.
    D-Link DNS-321 Affected: 20240814
    Create a notification for this product.
    D-Link DNR-322L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-323 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-325 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-326 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-327L Affected: 20240814
    Create a notification for this product.
    D-Link DNR-326 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-340L Affected: 20240814
    Create a notification for this product.
    D-Link DNS-343 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-345 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-726-4 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-1100-4 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-1200-05 Affected: 20240814
    Create a notification for this product.
    D-Link DNS-1550-04 Affected: 20240814
    Create a notification for this product.
    dlink dns-120_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-120_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dnr-202l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dnr-202l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-315l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-315l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-320_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-320_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-320l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-320l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-320lw_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-320lw_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-321_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-321_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dnr-322l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dnr-322l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-323_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-323_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-325_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-325_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-326_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-326_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-327l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-327l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dnr-326_firmware Affected: 20240814
        cpe:2.3:o:dlink:dnr-326_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-340l_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-340l_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-343_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-343_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-345_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-345_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-726-4_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-726-4_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-1100-4_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-1100-4_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-1200-05_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-1200-05_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    dlink dns-1550-04_firmware Affected: 20240814
        cpe:2.3:o:dlink:dns-1550-04_firmware:20240814:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-120_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-120_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dnr-202l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dnr-202l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-315l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-315l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-320_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-320_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-320l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-320l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-320lw_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-320lw_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-321_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-321_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dnr-322l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dnr-322l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-323_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-323_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-325_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-325_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-326_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-326_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-327l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-327l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dnr-326_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dnr-326_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-340l_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-340l_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-343_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-343_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-345_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-345_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-726-4_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-726-4_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-1100-4_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-1100-4_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-1200-05_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-1200-05_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:dlink:dns-1550-04_firmware:20240814:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "dns-1550-04_firmware",
                "vendor": "dlink",
                "versions": [
                  {
                    "status": "affected",
                    "version": "20240814"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-7922",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-19T18:05:19.786796Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-19T18:23:40.353Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "DNS-120",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNR-202L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-315L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-320",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-320L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-320LW",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-321",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNR-322L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-323",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-325",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-326",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-327L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNR-326",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-340L",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-343",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-345",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-726-4",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-1100-4",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-1200-05",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            },
            {
              "product": "DNS-1550-04",
              "vendor": "D-Link",
              "versions": [
                {
                  "status": "affected",
                  "version": "20240814"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "BuaaI0TTeam (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced."
            },
            {
              "lang": "de",
              "value": "Eine Schwachstelle wurde in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 bis 20240814 gefunden. Sie wurde als kritisch eingestuft. Betroffen davon ist die Funktion cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist der Datei /cgi-bin/myMusic.cgi. Durch das Beeinflussen mit unbekannten Daten kann eine command injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei \u00fcber das Netzwerk erfolgen. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 6.5,
                "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-19T15:00:06.847Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-275108 | D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.275108"
            },
            {
              "name": "VDB-275108 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.275108"
            },
            {
              "name": "Submit #391669 | D-Link DNS 320/320L/321/323/325/327L Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.391669"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_create_playlist.md"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_get_tracks_list.md"
            }
          ],
          "tags": [
            "unsupported-when-assigned"
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-08-19T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2024-08-19T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-08-19T11:49:33.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2024-7922",
        "datePublished": "2024-08-19T15:00:06.847Z",
        "dateReserved": "2024-08-19T09:43:35.228Z",
        "dateUpdated": "2024-08-19T18:23:40.353Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }