Dlink Dwr-912 Firmware vulnerabilities
3 known vulnerabilities affecting dlink/dwr-912_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2018-10824CRITICALCVSS 9.8PoC≤ 2.022018-10-17
CVE-2018-10824 [CRITICAL] CWE-22 CVE-2018-10824: An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. The administrative password is stored in plaintext in the /tmp/csman/0 file. An attacker having a directory traversal (or LFI)
nvd
CVE-2018-10823HIGHCVSS 8.8ExploitedPoC≤ 2.022018-10-17
CVE-2018-10823 [HIGH] CWE-78 CVE-2018-10823: An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02,
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internal
nvd
CVE-2018-10822HIGHCVSS 7.5PoC≤ 2.022018-10-17
CVE-2018-10822 [HIGH] CVE-2018-10822: Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L thro
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers to read arbitrary files via a /.. or // after "GET /uir" in an HTTP request. NOTE:
nvd