Dlink Dsr-500N Firmware vulnerabilities

5 known vulnerabilities affecting dlink/dsr-500n_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-39615CRITICALCVSS 9.8v1.022021-08-23
CVE-2021-39615 [CRITICAL] CWE-798 CVE-2021-39615: D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the ' D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be able to log in via SSH or Telnet and thus gain access to the underlying embedded Linux operating system on the device. Fixed in v
nvd
CVE-2013-5945CRITICALCVSS 9.8PoCfixed in 1.08b772020-02-11
CVE-2013-5945 [CRITICAL] CWE-89 CVE-2013-5945: Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenti
nvd
CVE-2013-5946CRITICALCVSS 10.0≤ 1.08b51v1.02b11+9 more2013-12-19
CVE-2013-5946 [CRITICAL] CWE-78 CVE-2013-5946: The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "Pin
nvd
CVE-2013-7004HIGHCVSS 7.8≤ 1.08b51v1.02b11+9 more2013-12-19
CVE-2013-7004 [HIGH] CWE-255 CVE-2013-7004: D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR- D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 have a hardcoded account of username gkJ9232xXyruTRmY, which makes it easier for remote attackers to obtain access by leveraging knowledge of th
nvd
CVE-2013-7005MEDIUMCVSS 4.9≤ 1.08b51v1.02b11+9 more2013-12-19
CVE-2013-7005 [MEDIUM] CWE-200 CVE-2013-7005: D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR- D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive information by reading the Users[#]["Password"] fields in
nvd