Dlink Dsl-3782 Firmware vulnerabilities

17 known vulnerabilities affecting dlink/dsl-3782_firmware.

Total CVEs
17
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-25894HIGHCVSS 8.0v1.012025-02-18
CVE-2025-25894 [HIGH] CWE-78 CVE-2025-25894: An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and s An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
nvd
CVE-2025-25895HIGHCVSS 8.0v1.012025-02-18
CVE-2025-25895 [HIGH] CWE-78 CVE-2025-25895: An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type pa An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the public_type parameter. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
nvd
CVE-2025-25893HIGHCVSS 8.0v1.012025-02-18
CVE-2025-25893 [HIGH] CWE-78 CVE-2025-25893: An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the inIP, insPort, inePort, exsPort, exePort, and protocol parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.
nvd
CVE-2025-25896MEDIUMCVSS 5.7v1.012025-02-18
CVE-2025-25896 [MEDIUM] CWE-121 CVE-2025-25896: A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the destination, netmask, and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
nvd
CVE-2025-25892MEDIUMCVSS 5.7v1.012025-02-18
CVE-2025-25892 [MEDIUM] CWE-121 CVE-2025-25892: A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, ds A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
nvd
CVE-2025-25891MEDIUMCVSS 5.7v1.012025-02-18
CVE-2025-25891 [MEDIUM] CWE-121 CVE-2025-25891: A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destinatio A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01, triggered by the destination, netmask and gateway parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
nvd
CVE-2024-56914MEDIUMCVSS 5.7v1.012025-01-22
CVE-2024-56914 [MEDIUM] CWE-120 CVE-2024-56914: D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp. D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.
nvd
CVE-2023-44959HIGHCVSS 8.8≤ 1.032023-10-10
CVE-2023-44959 [HIGH] CWE-77 CVE-2023-44959: An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arb An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.
nvd
CVE-2023-27216HIGHCVSS 8.8v1.032023-04-12
CVE-2023-27216 [HIGH] CWE-78 CVE-2023-27216: An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.
nvd
CVE-2022-35192HIGHCVSS 7.5v1.012022-08-26
CVE-2022-35192 [HIGH] CWE-120 CVE-2022-35192: D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticat D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.
nvd
CVE-2022-35191MEDIUMCVSS 6.5v1.012022-08-23
CVE-2022-35191 [MEDIUM] CWE-404 CVE-2022-35191: D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticat D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.
nvd
CVE-2022-34528HIGHCVSS 8.8v1.01v1.032022-07-29
CVE-2022-34528 [HIGH] CWE-787 CVE-2022-34528: D-Link DSL-3782 v1.03 and below was discovered to contain a stack overflow via the function getAttrV D-Link DSL-3782 v1.03 and below was discovered to contain a stack overflow via the function getAttrValue.
nvd
CVE-2022-34527HIGHCVSS 8.8v1.01v1.032022-07-29
CVE-2022-34527 [HIGH] CWE-78 CVE-2022-34527: D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160.
nvd
CVE-2021-40284MEDIUMCVSS 6.5veu_1.01veu_1.032021-09-09
CVE-2021-40284 [MEDIUM] CWE-120 CVE-2021-40284: D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of servi D-Link DSL-3782 EU v1.01:EU v1.03 is affected by a buffer overflow which can cause a denial of service. This vulnerability exists in the web interface "/cgi-bin/New_GUI/Igmp.asp". Authenticated remote attackers can trigger this vulnerability by sending a long string in parameter 'igmpsnoopEnable' via an HTTP request.
nvd
CVE-2018-17990HIGHCVSS 8.8v1.012019-04-01
CVE-2018-17990 [HIGH] CWE-78 CVE-2018-17990: An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulne An issue was discovered on D-Link DSL-3782 devices with firmware 1.01. An OS command injection vulnerability in Acl.asp allows a remote authenticated attacker to execute arbitrary OS commands via the ScrIPaddrEndTXT parameter.
nvd
CVE-2018-17989MEDIUMCVSS 5.4v1.012019-04-01
CVE-2018-17989 [MEDIUM] CWE-79 CVE-2018-17989: A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 A stored XSS vulnerability exists in the web interface on D-Link DSL-3782 devices with firmware 1.01 that allows authenticated attackers to inject a JavaScript or HTML payload inside the ACL page. The injected payload would be executed in a user's browser when "/cgi-bin/New_GUI/Acl.asp" is requested.
nvd
CVE-2018-8898CRITICALCVSS 9.8PoCv3.10.0.242018-05-23
CVE-2018-8898 [CRITICAL] CWE-287 CVE-2018-8898: A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.
nvd