VendorsD-Linkdir-823g_firmware1.0.2b05
Vulnerabilities

D-Link DIR-823G Firmware 1.0.2b05

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

36CVEs
CVE-2020-25367
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
Published 2021-11-04 · Modified
9.8EPSS 0.086
CVE-2023-43241
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.
Published 2023-09-21 · Modified
9.8EPSS 0.013
CVE-2023-43235
D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.
Published 2023-09-21 · Modified
9.8EPSS 0.013
CVE-2023-29665
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
Published 2023-04-17 · Modified
9.8EPSS 0.012
CVE-2019-15529
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
Published 2019-08-23 · Modified
9.0EPSS 0.077
CVE-2019-15530
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
Published 2019-08-23 · Modified
9.0EPSS 0.043
CVE-2019-15527
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.
Published 2019-08-23 · Modified
9.0EPSS 0.041
CVE-2019-15526
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
Published 2019-08-23 · Modified
9.0EPSS 0.041
CVE-2019-15528
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.
Published 2019-08-23 · Modified
9.0EPSS 0.041
CVE-2024-51023
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
Published 2024-11-05 · Analyzed
8.8EPSS 0.015
CVE-2024-27655
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
Published 2024-02-29 · Analyzed
8.8EPSS 0.012
CVE-2024-27657
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
Published 2024-02-29 · Analyzed
8.8EPSS 0.012
CVE-2024-27656
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.
Published 2024-02-29 · Analyzed
8.8EPSS 0.006
CVE-2026-11492
D-Link DIR-823G vsftpd vsftpd.conf least privilege violation
Published 2026-06-08 · Analyzed
8.8EPSS 0.005
CVE-2024-51024
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.
Published 2024-11-05 · Analyzed
8.0EPSS 0.014
CVE-2023-44839
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Encryption parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.081
CVE-2025-60332
A NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
Published 2025-10-22 · Analyzed
7.5EPSS 0.050
CVE-2023-44831
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Type parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44837
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44836
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44835
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44834
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the StartTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44833
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44838
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the TXPower parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44829
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44830
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.009
CVE-2023-44832
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the MacAddress parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.008
CVE-2023-44828
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2023-10-05 · Modified
7.5EPSS 0.008
CVE-2026-4193
D-Link DIR-823G goahead UpdateClientInfo access control
Published 2026-03-15 · Analyzed
7.5EPSS 0.008
CVE-2025-60331
D-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-22 · Analyzed
7.5EPSS 0.006
CVE-2024-33345
D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-04-29 · Analyzed
6.5EPSS 0.008
CVE-2024-27660
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-02-29 · Analyzed
6.5EPSS 0.006
CVE-2024-27659
D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-02-29 · Analyzed
6.5EPSS 0.006
CVE-2024-27658
D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-02-29 · Analyzed
6.5EPSS 0.006
CVE-2024-27662
D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-02-29 · Analyzed
6.5EPSS 0.004
CVE-2024-27661
D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-02-29 · Analyzed
6.5EPSS 0.004