cbcvebase.

Dlink Dir-3040 Firmware vulnerabilities

25 known vulnerabilities affecting dlink/dir-3040_firmware.

Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH8MEDIUM14

Vulnerabilities

Page 2 of 2
CVE-2023-41226P3MEDIUMCVSS 6.8≤ 1.20b032024-05-03
CVE-2023-41226 [MEDIUM] CWE-121 CVE-2023-41226: D-Link DIR-3040 prog.cgi SetMyDLinkRegistration Stack-Based Buffer Overflow Remote Code Execution Vu D-Link DIR-3040 prog.cgi SetMyDLinkRegistration Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the prog.cgi b
nvd
CVE-2023-41224P3MEDIUMCVSS 6.8≤ 1.20b032024-05-03
CVE-2023-41224 [MEDIUM] CWE-121 CVE-2023-41224: D-Link DIR-3040 prog.cgi SetDeviceSettings Stack-Based Buffer Overflow Remote Code Execution Vulnera D-Link DIR-3040 prog.cgi SetDeviceSettings Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3040 routers. Authentication is required to exploit this vulnerability. The specific flaw exists within the prog.cgi binary
nvd
CVE-2021-21817P3HIGHCVSS 7.5v1.13b032021-07-16
CVE-2021-21817 [HIGH] CWE-200 CVE-2021-21817: An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LI An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.
nvd
CVE-2021-21818P3HIGHCVSS 7.5v1.13b032021-07-16
CVE-2021-21818 [HIGH] CWE-259 CVE-2021-21818: A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK D A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of requests to trigger this vulnerability.
nvd
CVE-2024-5294P4MEDIUMCVSS 6.5v120b032024-05-23
CVE-2024-5294 [MEDIUM] CWE-401 CVE-2024-5294: D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulne D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of D-Link DIR-3040 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the prog.cgi program,
nvd
Dlink Dir-3040 Firmware vulnerabilities | cvebase