VendorsD-Linkdir-300all versions
Vulnerabilities

D-Link dir-300

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2013-10069
D-Link Devices Unauthenticated RCE
Published 2025-08-05 · Analyzed
10.0EPSS 0.119
CVE-2013-7471
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.
Published 2019-06-11 · Modified
9.8EPSS 0.240
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
Published 2025-08-01 · Analyzed
9.8EPSS 0.171
CVE-2023-31814
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.
Published 2023-05-23 · Modified
9.8EPSS 0.009
CVE-2024-41616
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
Published 2024-08-06 · Analyzed
9.8EPSS 0.008
CVE-2013-10050
D-Link Devices tools_vct.xgi Authenticated RCE
Published 2025-08-01 · Modified
8.8EPSS 0.136
CVE-2011-4723
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
Published 2011-12-20 · Analyzed
6.8KEVEPSS 0.031
CVE-2024-0717
D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
Published 2024-01-19 · Modified
5.3EPSS 0.182