VendorsD-Linkr15any version
Vulnerabilities

D-Link R15 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-60854
A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.
Published 2025-12-02 · Analyzed
9.8EPSS 0.012
CVE-2023-41603
D-Link R15 before v1.08.02 was discovered to contain no firewall restrictions for IPv6 traffic. This allows attackers to arbitrarily access any services running on the device that may be inadvertently listening via IPv6.
Published 2024-01-10 · Modified
5.3EPSS 0.005