VendorsD-Linkdap-1360_firmwareall versions
Vulnerabilities

D-Link DAP-1360 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-32136
D-Link DAP-1360 webproc var:menu Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.012
CVE-2023-32143
D-Link DAP-1360 webupg UPGCGI_CheckAuth Numeric Truncation Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.011
CVE-2023-32141
D-Link DAP-1360 webproc WEB_DisplayPage Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.011
CVE-2023-32142
D-Link DAP-1360 webproc var:page Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.011
CVE-2023-32146
D-Link DAP-1360 Multiple Parameters Stack-Based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.011
CVE-2023-32139
D-Link DAP-1360 webproc Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.010
CVE-2023-32144
D-Link DAP-1360 webproc COMM_MakeCustomMsg Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.010
CVE-2023-32138
D-Link DAP-1360 webproc Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2023-32145
D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability
Published 2024-05-03 · Analyzed
8.8EPSS 0.009
CVE-2023-32140
D-Link DAP-1360 webproc var:sys_Token Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2024-05-03 · Analyzed
7.5EPSS 0.009
CVE-2014-10025
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that change the (1) Enable Wireless, (2) MBSSID, (3) BSSID, (4) Hide Access Point, (5) SSID, (6) Country, (7) Channel, (8) Wireless mode, or (9) Max Associated Clients setting via a crafted request to index.cgi.
Published 2015-01-13 · Modified
6.8EPSS 0.008
CVE-2014-10027
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP-1360 router with firmware 2.5.4 and earlier allow remote attackers to hijack the authentication of unspecified users for requests that (1) change the MAC filter restrict mode, (2) add a MAC address to the filter, or (3) remove a MAC address from the filter via a crafted request to index.cgi.
Published 2015-01-13 · Modified
6.8EPSS 0.008
CVE-2023-32137
D-Link DAP-1360 webproc WEB_DisplayPage Directory Traversal Information Disclosure Vulnerability
Published 2024-05-03 · Analyzed
6.5EPSS 0.012
CVE-2024-0717
D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
Published 2024-01-19 · Modified
5.3EPSS 0.182
CVE-2014-10026
index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by setting the client_login cookie to admin.
Published 2015-01-13 · Modified
5.0EPSS 0.020
CVE-2014-10028
Cross-site scripting (XSS) vulnerability in D-Link DAP-1360 router with firmware 2.5.4 and later allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi when res_config_id is set to 41.
Published 2015-01-13 · Modified
4.3EPSS 0.010