Dlink Dir-878 Firmware vulnerabilities
39 known vulnerabilities affecting dlink/dir-878_firmware.
Total CVEs
39
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH24MEDIUM5
Vulnerabilities
Page 2 of 2
CVE-2023-24798P3CRITICALCVSS 9.8v1.20b052023-04-07
CVE-2023-24798 [CRITICAL] CWE-787 CVE-2023-24798: D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_475FB0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2023-24799P3CRITICALCVSS 9.8v1.20b052023-04-07
CVE-2023-24799 [CRITICAL] CWE-787 CVE-2023-24799: D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
nvd
CVE-2024-48638P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48638 [HIGH] CWE-78 CVE-2024-48638: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48636P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48636 [HIGH] CWE-78 CVE-2024-48636: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48635P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48635 [HIGH] CWE-78 CVE-2024-48635: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48637P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48637 [HIGH] CWE-78 CVE-2024-48637: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48629P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48629 [HIGH] CWE-78 CVE-2024-48629: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48631P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48631 [HIGH] CWE-78 CVE-2024-48631: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48630P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48630 [HIGH] CWE-78 CVE-2024-48630: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2025-60676P3MEDIUMCVSS 6.5v1.01b042025-11-13
CVE-2025-60676 [MEDIUM] CWE-77 CVE-2025-60676: An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW
An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell commands executed via system(). An attacker can exploit this vulnerabilit
nvd
CVE-2022-26670P3HIGHCVSS 8.8≤ 1.20b052022-04-07
CVE-2022-26670 [HIGH] CWE-78 CVE-2022-26670: D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauth
D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attacker can perform command injection attack to execute arbitrary system commands to control the system or disrupt service.
nvd
CVE-2024-48633P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48633 [HIGH] CWE-78 CVE-2024-48633: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command inj
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2024-48632P3HIGHCVSS 8.0v1.30b082024-10-17
CVE-2024-48632 [HIGH] CWE-78 CVE-2024-48632: D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command inj
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
nvd
CVE-2022-1262P3HIGHCVSS 7.8v1.20b05v1.30b082022-04-11
CVE-2022-1262 [HIGH] CWE-78 CVE-2022-1262: A command injection vulnerability in the protest binary allows an attacker with access to the remote
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
nvd
CVE-2025-0481P3HIGHCVSS 7.5v1.032025-01-15
CVE-2025-0481 [HIGH] CWE-200 CVE-2025-0481: A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unkn
A vulnerability classified as problematic has been found in D-Link DIR-878 1.03. Affected is an unknown function of the file /dllog.cgi of the component HTTP POST Request Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2022-44202P3CRITICALCVSS 9.8v1.02b04v1.02b052022-11-22
CVE-2022-44202 [CRITICAL] CWE-787 CVE-2022-44202: D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
nvd
CVE-2022-44801P3CRITICALCVSS 9.8v1.02b052022-11-22
CVE-2022-44801 [CRITICAL] CVE-2022-44801: D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
nvd
CVE-2024-0717P3MEDIUMCVSS 5.3≤ 2024-01-122024-01-19
CVE-2024-0717 [MEDIUM] CWE-200 CVE-2024-0717: A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DI
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530,
nvd
CVE-2025-60674P3MEDIUMCVSS 6.8v1.01b042025-11-13
CVE-2025-60674 [MEDIUM] CWE-121 CVE-2025-60674: A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in
A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 bytes, causing a stack overflow. An attacker with physi
nvd
← Previous2 / 2