VendorsD-Linkdir-815_firmwareall versions
Vulnerabilities

D-Link dir-815 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2018-25115
D-Link DIR-110/412/600/615/645/815 RCE via service.cgi
Published 2025-08-27 · Analyzed
10.0EPSS 0.104
CVE-2014-8888
The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via vectors related to an "HTTP command injection issue."
Published 2018-04-12 · Modified
10.0EPSS 0.053
CVE-2023-51123
An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.
Published 2024-01-10 · Modified
9.8EPSS 0.244
CVE-2024-22651
There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.
Published 2024-01-24 · Modified
9.8EPSS 0.202
CVE-2015-0150
The remote administration UI in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to bypass intended access restrictions via unspecified vectors.
Published 2018-04-12 · Modified
9.8EPSS 0.021
CVE-2015-0152
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password.
Published 2018-04-12 · Modified
9.8EPSS 0.020
CVE-2018-10106
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.php?a=%0a_POST_SERVICES%3DDEVICE.ACCOUNT%0aAUTHORIZED_GROUP%3D1 request.
Published 2018-04-16 · Modified
9.8EPSS 0.019
CVE-2025-6328
D-Link DIR-815 hedwig.cgi sub_403794 stack-based overflow
Published 2025-06-20 · Analyzed
9.0EPSS 0.012
CVE-2015-0151
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
Published 2018-04-12 · Modified
8.8EPSS 0.011
CVE-2015-0153
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.
Published 2018-04-12 · Modified
7.5EPSS 0.019
CVE-2023-37758
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.
Published 2023-07-18 · Modified
7.5EPSS 0.014
CVE-2018-10107
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.
Published 2018-04-16 · Modified
6.1EPSS 0.011
CVE-2018-10108
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
Published 2018-04-16 · Modified
6.1EPSS 0.011
CVE-2020-25786
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header
Published 2020-09-19 · Modified
6.1EPSS 0.010
CVE-2024-0717
D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
Published 2024-01-19 · Modified
5.3EPSS 0.182