VendorsD-Linkdwr-932bany version
Vulnerabilities

D-Link DWR-932B any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2016-10182
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
Published 2017-01-30 · Modified
10.0EPSS 0.087
CVE-2016-10178
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
Published 2017-01-30 · Modified
10.0EPSS 0.073
CVE-2016-10177
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
Published 2017-01-30 · Modified
10.0EPSS 0.069
CVE-2016-10183
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
Published 2017-01-30 · Modified
7.5EPSS 0.056
CVE-2016-10184
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
Published 2017-01-30 · Modified
7.5EPSS 0.056
CVE-2016-10179
An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.
Published 2017-01-30 · Modified
7.5EPSS 0.049
CVE-2016-10180
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.
Published 2017-01-30 · Modified
7.5EPSS 0.044
CVE-2016-10185
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
Published 2017-01-30 · Modified
7.5EPSS 0.042
CVE-2016-10186
An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.
Published 2017-01-30 · Modified
7.5EPSS 0.042
CVE-2016-10181
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.
Published 2017-01-30 · Modified
7.5EPSS 0.039