Dlink Dar-8000-10 Firmware vulnerabilities

3 known vulnerabilities affecting dlink/dar-8000-10_firmware.

Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-4699MEDIUMCVSS 5.3≤ 202309222024-05-14
CVE-2024-4699 [MEDIUM] CWE-502 CVE-2024-4699: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The attack may be initiated remotely. The associated identifier of this vulnerabil
nvd
CVE-2023-4711HIGHCVSS 8.1≤ 202308192023-09-01
CVE-2023-4711 [MEDIUM] CWE-78 CVE-2023-4711: A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 202308 A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230819. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitatio
nvd
CVE-2023-4542CRITICALCVSS 9.8PoC≤ 2023-08-092023-08-25
CVE-2023-4542 [MEDIUM] CWE-78 CVE-2023-4542: A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The
nvd