Dlink Dir-885L Firmware vulnerabilities

4 known vulnerabilities affecting dlink/dir-885l_firmware.

Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH1

Vulnerabilities

Page 1 of 1
CVE-2023-36090CRITICALCVSS 9.8v1.022023-07-31
CVE-2023-36090 [CRITICAL] CWE-863 CVE-2023-36090: Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain esca Authentication Bypass vulnerability in D-Link DIR-885L FW102b01 allows remote attackers to gain escalated privileges via phpcgi. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2019-20213HIGHCVSS 7.5≤ 1.12b052020-01-02
CVE-2019-20213 [HIGH] CWE-74 CVE-2019-20213: D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUT D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
nvd
CVE-2019-17621CRITICALCVSS 9.8KEV≤ 1.12b052019-12-30
CVE-2019-17621 [CRITICAL] CWE-78 CVE-2019-17621: The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
nvd
CVE-2019-16190CRITICALCVSS 9.8≤ 1.202019-09-09
CVE-2019-16190 [CRITICAL] CWE-287 CVE-2019-16190: SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.
nvd