Dlink Dir-859 A3 Firmware vulnerabilities
3 known vulnerabilities affecting dlink/dir-859_a3_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-57045CRITICALCVSS 9.8PoCfixed in 1.052025-02-18
CVE-2024-57045 [CRITICAL] CWE-287 CVE-2024-57045: A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unaut
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
nvd
CVE-2022-25106MEDIUMCVSS 5.5v1.052022-03-04
CVE-2022-25106 [MEDIUM] CWE-787 CVE-2022-25106: D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacg
D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
nvd
CVE-2019-17508CRITICALCVSS 9.8v1.062019-10-11
CVE-2019-17508 [CRITICAL] CWE-78 CVE-2019-17508: On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command in
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.
nvd