VendorsD-Linkdir-845lall versions
Vulnerabilities

D-Link DIR-845L

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-36756
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
Published 2022-08-28 · Modified
9.8EPSS 0.032
CVE-2022-36755
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
Published 2022-08-28 · Modified
9.8EPSS 0.014
CVE-2022-38557
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
Published 2022-08-28 · Modified
9.8EPSS 0.010
CVE-2024-33110
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
Published 2024-05-06 · Analyzed
9.1EPSS 0.007
CVE-2024-29385
DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.
Published 2024-03-22 · Analyzed
9.0EPSS 0.016
CVE-2024-29366
A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
Published 2024-03-22 · Analyzed
8.8EPSS 0.024
CVE-2024-33112
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
Published 2024-05-06 · Analyzed
7.5EPSS 0.065
CVE-2024-33111
D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.
Published 2024-05-06 · Analyzed
5.4EPSS 0.008
CVE-2024-33113
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
Published 2024-05-06 · Analyzed
5.3EPSS 0.034