cbcvebase.

Dlink Dap-1325 Firmware vulnerabilities

37 known vulnerabilities affecting dlink/dap-1325_firmware.

Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH36MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2023-41209P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41209 [HIGH] CWE-121 CVE-2023-41209: D-Link DAP-1325 SetHostIPv6StaticSettings StaticDNS1 Stack-based Buffer Overflow Remote Code Executi D-Link DAP-1325 SetHostIPv6StaticSettings StaticDNS1 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the han
nvd
CVE-2023-41212P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41212 [HIGH] CWE-121 CVE-2023-41212: D-Link DAP-1325 SetTriggerAPValidate Key Stack-based Buffer Overflow Remote Code Execution Vulnerabi D-Link DAP-1325 SetTriggerAPValidate Key Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of XML
nvd
CVE-2023-41202P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41202 [HIGH] CWE-121 CVE-2023-41202: D-Link DAP-1325 SetAPLanSettings Mode Stack-based Buffer Overflow Remote Code Execution Vulnerabilit D-Link DAP-1325 SetAPLanSettings Mode Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of XML da
nvd
CVE-2023-41206P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41206 [HIGH] CWE-121 CVE-2023-41206: D-Link DAP-1325 SetHostIPv6Settings IPv6Mode Stack-based Buffer Overflow Remote Code Execution Vulne D-Link DAP-1325 SetHostIPv6Settings IPv6Mode Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of
nvd
CVE-2023-41204P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41204 [HIGH] CWE-121 CVE-2023-41204: D-Link DAP-1325 SetAPLanSettings SecondaryDNS Stack-based Buffer Overflow Remote Code Execution Vuln D-Link DAP-1325 SetAPLanSettings SecondaryDNS Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling o
nvd
CVE-2023-41205P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41205 [HIGH] CWE-121 CVE-2023-41205: D-Link DAP-1325 SetAPLanSettings SubnetMask Stack-based Buffer Overflow Remote Code Execution Vulner D-Link DAP-1325 SetAPLanSettings SubnetMask Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of
nvd
CVE-2023-41208P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41208 [HIGH] CWE-121 CVE-2023-41208: D-Link DAP-1325 SetHostIPv6StaticSettings StaticDefaultGateway Stack-based Buffer Overflow Remote Co D-Link DAP-1325 SetHostIPv6StaticSettings StaticDefaultGateway Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists with
nvd
CVE-2023-41210P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41210 [HIGH] CWE-121 CVE-2023-41210: D-Link DAP-1325 SetHostIPv6StaticSettings StaticDNS2 Stack-based Buffer Overflow Remote Code Executi D-Link DAP-1325 SetHostIPv6StaticSettings StaticDNS2 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the han
nvd
CVE-2023-44407P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-44407 [HIGH] CWE-121 CVE-2023-44407: D-Link DAP-1325 SetAPLanSettings Gateway Stack-based Buffer Overflow Remote Code Execution Vulnerabi D-Link DAP-1325 SetAPLanSettings Gateway Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of XML
nvd
CVE-2023-44408P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-44408 [HIGH] CWE-121 CVE-2023-44408: D-Link DAP-1325 SetAPLanSettings IPAddr Stack-based Buffer Overflow Remote Code Execution Vulnerabil D-Link DAP-1325 SetAPLanSettings IPAddr Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of XML
nvd
CVE-2023-44404P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-44404 [HIGH] CWE-121 CVE-2023-44404: D-Link DAP-1325 get_value_from_app Stack-based Buffer Overflow Remote Code Execution Vulnerability. D-Link DAP-1325 get_value_from_app Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of XML data p
nvd
CVE-2023-44406P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-44406 [HIGH] CWE-121 CVE-2023-44406: D-Link DAP-1325 SetAPLanSettings DeviceName Stack-based Buffer Overflow Remote Code Execution Vulner D-Link DAP-1325 SetAPLanSettings DeviceName Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of
nvd
CVE-2023-44405P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-44405 [HIGH] CWE-121 CVE-2023-44405: D-Link DAP-1325 get_value_of_key Stack-based Buffer Overflow Remote Code Execution Vulnerability. Th D-Link DAP-1325 get_value_of_key Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of XML data pr
nvd
CVE-2023-41187P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-41187 [HIGH] CWE-306 CVE-2023-41187: D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This vulnerability D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the HNAP interface. The
nvd
CVE-2023-44409P2HIGHCVSS 8.8fixed in 1.09b032024-05-03
CVE-2023-44409 [HIGH] CWE-121 CVE-2023-44409: D-Link DAP-1325 SetSetupWizardStatus Enabled Stack-based Buffer Overflow Remote Code Execution Vulne D-Link DAP-1325 SetSetupWizardStatus Enabled Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of
nvd
CVE-2023-53896P3HIGHCVSS 7.5v1.012025-12-16
CVE-2023-53896 [HIGH] CWE-306 CVE-2023-53896: D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows una D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
nvd
CVE-2023-41186P3MEDIUMCVSS 6.5fixed in 1.09b032024-05-03
CVE-2023-41186 [MEDIUM] CWE-306 CVE-2023-41186: D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to access various functionality on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the CGI interfa
nvd
Dlink Dap-1325 Firmware vulnerabilities | cvebase