cbcvebase.

D-Link Dns-320 vulnerabilities

59 known vulnerabilities affecting d-link/dns-320.

Total CVEs
59
CISA KEV
0
Public exploits
2
Exploited in wild
3
Severity breakdown
CRITICAL36HIGH15MEDIUM8

Vulnerabilities

Page 3 of 3
CVE-2024-7832P2HIGHCVSS 8.8v202408142024-08-15
CVE-2024-7832 [HIGH] CWE-120 CVE-2024-7832: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cg
nvd
CVE-2024-7849P2HIGHCVSS 8.8v202408142024-08-16
CVE-2024-7849 [HIGH] CWE-120 CVE-2024-7849: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Li ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This affects the function cgi_cre
nvd
CVE-2026-8272P2HIGHCVSS 7.2v2.06B012026-05-11
CVE-2026-8272 [HIGH] CWE-77 CVE-2026-8272: A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rena A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
nvd
CVE-2026-8271P2HIGHCVSS 7.2v2.06B012026-05-11
CVE-2026-8271 [HIGH] CWE-77 CVE-2026-8271: A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_s A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit of the file /cgi-bin/network_mgr.cgi. The manipulation leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly avai
nvd
CVE-2024-7715P3MEDIUMCVSS 6.3v202408122024-08-13
CVE-2024-7715 [MEDIUM] CWE-77 CVE-2024-7715: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240812. It has been classified as critical. This affects the function sprin
nvd
CVE-2026-8273P3HIGHCVSS 7.2v2.06B012026-05-11
CVE-2026-8273 [HIGH] CWE-77 CVE-2026-8273: A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely.
nvd
CVE-2026-16327P3HIGHCVSS 7.3v1.0.22026-07-21
CVE-2026-16327 [HIGH] CWE-284 CVE-2026-16327: A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing o A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-16447P3HIGHCVSS 7.3v1.0.22026-07-21
CVE-2026-16447 [HIGH] CWE-284 CVE-2026-16447: A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-16331P3HIGHCVSS 7.3v1.0.22026-07-21
CVE-2026-16331 [HIGH] CWE-284 CVE-2026-16331: A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-16330P3HIGHCVSS 7.3v1.0.22026-07-21
CVE-2026-16330 [HIGH] CWE-284 CVE-2026-16330: A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has
nvd
CVE-2026-16332P3HIGHCVSS 7.3v1.0.22026-07-21
CVE-2026-16332 [HIGH] CWE-284 CVE-2026-16332: A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file / A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
CVE-2026-16329P3HIGHCVSS 7.3v1.0.22026-07-21
CVE-2026-16329 [HIGH] CWE-284 CVE-2026-16329: A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-16448P3MEDIUMCVSS 6.3v202602052026-07-21
CVE-2026-16448 [MEDIUM] CWE-74 CVE-2026-16448: A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-3 A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. T
nvd
CVE-2024-8460P3MEDIUMCVSS 5.9v2.02b012024-09-05
CVE-2024-8460 [MEDIUM] CWE-200 CVE-2024-8460: A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affe A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality of the file /cgi-bin/widget_api.cgi of the component Web Management Interface. The manipulation of the argument getHD/getSer/getSys leads to information disclosure. The attack may be launched remotely. Th
nvd
CVE-2026-5311P3MEDIUMCVSS 5.3v202602052026-04-01
CVE-2026-5311 [MEDIUM] CWE-266 CVE-2026-5311: A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-32 A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function Webdav_Access_List of the file /cgi-bin/file_center.cgi. Perfor
nvd
CVE-2026-5215P4MEDIUMCVSS 5.3v202602052026-03-31
CVE-2026-5215 [MEDIUM] CWE-266 CVE-2026-5215: A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_get_ipv6 of the file /cgi-bin/network_mgr.cgi. Such m
nvd
CVE-2026-5312P4MEDIUMCVSS 5.3v202602052026-04-01
CVE-2026-5312 [MEDIUM] CWE-266 CVE-2026-5312: A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function FMT_restart/Status_HDInfo/SMART_List/ScanDisk_i
nvd
CVE-2024-8461P4MEDIUMCVSS 5.3v2.02b012024-09-05
CVE-2024-8461 [MEDIUM] CWE-200 CVE-2024-8461: A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affe A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2024-10916P4MEDIUMCVSS 5.3v202410282024-11-06
CVE-2024-10916 [MEDIUM] CWE-200 CVE-2024-10916: A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and D A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the file /xml/info.xml of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed
nvd
D-Link Dns-320 vulnerabilities | cvebase