Dlink Dap-2622 Firmware vulnerabilities
54 known vulnerabilities affecting dlink/dap-2622_firmware.
Total CVEs
54
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH51MEDIUM3
Vulnerabilities
Page 3 of 3
CVE-2023-37314P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-37314 [HIGH] CWE-121 CVE-2023-37314: D-Link DAP-2622 DDP Set IPv6 Address Auth Username Stack-based Buffer Overflow Remote Code Execution
D-Link DAP-2622 DDP Set IPv6 Address Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP s
nvd
CVE-2023-37319P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-37319 [HIGH] CWE-121 CVE-2023-37319: D-Link DAP-2622 DDP Set IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability
D-Link DAP-2622 DDP Set IPv6 Address Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The is
nvd
CVE-2023-37326P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-37326 [HIGH] CWE-121 CVE-2023-37326: D-Link DAP-2622 DDP Set Wireless Info Auth Password Stack-based Buffer Overflow Remote Code Executio
D-Link DAP-2622 DDP Set Wireless Info Auth Password Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP
nvd
CVE-2023-37313P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-37313 [HIGH] CWE-121 CVE-2023-37313: D-Link DAP-2622 DDP Set IPv4 Address Auth Username Stack-based Buffer Overflow Remote Code Execution
D-Link DAP-2622 DDP Set IPv4 Address Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP s
nvd
CVE-2023-37312P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-37312 [HIGH] CWE-121 CVE-2023-37312: D-Link DAP-2622 DDP Set Device Info Device Name Stack-based Buffer Overflow Remote Code Execution Vu
D-Link DAP-2622 DDP Set Device Info Device Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP serv
nvd
CVE-2023-35757P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-07
CVE-2023-35757 [HIGH] CWE-121 CVE-2023-35757: D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulne
D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service
nvd
CVE-2023-35718P2HIGHCVSS 8.8v1.002024-05-03
CVE-2023-35718 [HIGH] CWE-121 CVE-2023-35718: D-Link DAP-2622 DDP Change ID Password Auth Password Stack-based Buffer Overflow Remote Code Executi
D-Link DAP-2622 DDP Change ID Password Auth Password Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP
nvd
CVE-2023-35735P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-35735 [HIGH] CWE-121 CVE-2023-35735: D-Link DAP-2622 DDP Change ID Password New Username Stack-based Buffer Overflow Remote Code Executio
D-Link DAP-2622 DDP Change ID Password New Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP
nvd
CVE-2023-35733P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-35733 [HIGH] CWE-121 CVE-2023-35733: D-Link DAP-2622 DDP Change ID Password Auth Username Stack-based Buffer Overflow Remote Code Executi
D-Link DAP-2622 DDP Change ID Password Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP
nvd
CVE-2023-35736P2HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-35736 [HIGH] CWE-121 CVE-2023-35736: D-Link DAP-2622 DDP Change ID Password New Password Stack-based Buffer Overflow Remote Code Executio
D-Link DAP-2622 DDP Change ID Password New Password Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP
nvd
CVE-2023-35724P3HIGHCVSS 8.8fixed in 1.10b03r0222024-05-03
CVE-2023-35724 [HIGH] CWE-798 CVE-2023-35724: D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vu
D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the CLI service, which listens on
nvd
CVE-2023-44416P3MEDIUMCVSS 6.8v1.002024-05-03
CVE-2023-44416 [MEDIUM] CWE-78 CVE-2023-44416: D-Link DAP-2622 Telnet CLI Command Injection Remote Code Execution Vulnerability. This vulnerability
D-Link DAP-2622 Telnet CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622. Authentication is required to exploit this vulnerability.
The specific flaw exists within the CLI service, which listens on TCP port 23. The iss
nvd
CVE-2023-35750P3MEDIUMCVSS 6.5fixed in 1.10b03r0222024-05-03
CVE-2023-35750 [MEDIUM] CWE-200 CVE-2023-35750: D-Link DAP-2622 DDP Get SSID List WPA PSK Information Disclosure Vulnerability. This vulnerability a
D-Link DAP-2622 DDP Get SSID List WPA PSK Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The issue results
nvd
CVE-2023-37325P4MEDIUMCVSS 5.4v1.002024-05-07
CVE-2023-37325 [MEDIUM] CWE-306 CVE-2023-37325: D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows ne
D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the DDP service. The iss
nvd
← Previous3 / 3