Dlink Dir-860L Firmware vulnerabilities
10 known vulnerabilities affecting dlink/dir-860l_firmware.
Total CVEs
10
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL4MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2025-9026MEDIUMCVSS 6.9v2.04.b042025-08-15
CVE-2025-9026 [MEDIUM] CWE-77 CVE-2025-9026: A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main o
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cgibin of the component Simple Service Discovery Protocol. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability
nvd
CVE-2024-37605MEDIUMCVSS 6.5v2.04.b04_ic5b2024-12-17
CVE-2024-37605 [MEDIUM] CWE-476 CVE-2024-37605: A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause
A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
nvd
CVE-2024-42812CRITICALCVSS 9.8v2.0.32024-08-19
CVE-2024-42812 [CRITICAL] CWE-120 CVE-2024-42812: In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verific
In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
nvd
CVE-2024-41611CRITICALCVSS 9.8v1.10b042024-07-30
CVE-2024-41611 [CRITICAL] CWE-798 CVE-2024-41611: In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials,
In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.
nvd
CVE-2020-25786MEDIUMCVSS 6.1v1.10b042020-09-19
CVE-2020-25786 [MEDIUM] CWE-79 CVE-2020-25786: webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that
nvd
CVE-2018-20114CRITICALCVSS 9.8v2.03.b032019-01-02
CVE-2018-20114 [CRITICAL] CWE-78 CVE-2018-20114: On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS co
On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-6530.
nvd
CVE-2018-6530CRITICALCVSS 9.8KEVPoC≤ 1.10b042018-03-06
CVE-2018-6530 [CRITICAL] CWE-78 CVE-2018-6530: OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to
nvd
CVE-2018-6527MEDIUMCVSS 6.1≤ a1_fw110b042018-03-06
CVE-2018-6527 [MEDIUM] CWE-79 CVE-2018-6527: XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04
XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted deviceid parameter to soap.cgi.
nvd
CVE-2018-6528MEDIUMCVSS 6.1≤ a1_fw110b042018-03-06
CVE-2018-6528 [MEDIUM] CWE-79 CVE-2018-6528: XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and p
XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to soap.cgi.
nvd
CVE-2018-6529MEDIUMCVSS 6.1≤ a1_fw110b042018-03-06
CVE-2018-6529 [MEDIUM] CWE-79 CVE-2018-6529: XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and pr
XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted Treturn parameter to soap.cgi.
nvd