📦

di-624

Vendor: d-link

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 6.77% Exploit Prob.
Latest CVE CVE-2006-3687 Jul 21

Security Vulnerability Index

Page 1 / 1
7.5 CVSS
CVE-2006-3687
Exploit Found

Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to UDP port 1900.

EPSS: 19.13%
5.0 CVSS
CVE-2005-4723
Exploit Found

D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.

EPSS: 3.23%
5.1 CVSS
CVE-2004-0615
Exploit Found

Cross-site scripting (XSS) vulnerability in D-Link DI-614+ SOHO router running firmware 2.30, and DI-704 SOHO router running firmware 2.60B2, and DI-624, allows remote attackers to inject arbitrary script or HTML via the DHCP HOSTNAME option in a DHCP request.

EPSS: 2.43%
5.0 CVSS

Integer signedness error in D-Link AirPlus DI-614+ running firmware 2.30 and earlier allows remote attackers to cause a denial of service (IP lease depletion) via a DHCP request with the LEASETIME option set to -1, which makes the DHCP lease valid for thirteen or more years.

EPSS: 2.28%