📦

di-524

Vendor: d-link

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 6.07% Exploit Prob.
Latest CVE CVE-2019-11017 Apr 18

Security Vulnerability Index

Page 1 / 1
4.8 CVSS
CVE-2019-11017
Exploit Found

On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm, /smap.htm, and /cgi-bin/smap, as demonstrated by the cgi-bin/smap RC parameter.

EPSS: 1.52%
8.0 CVSS
CVE-2017-5633
Exploit Found

Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.

EPSS: 3.96%
7.8 CVSS

Multiple buffer overflows in the web interface on the D-Link DI-524 router allow remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact via (1) a long username or (2) an HTTP header with a large name and an empty value.

EPSS: 2.50%
7.5 CVSS
CVE-2006-3687
Exploit Found

Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to UDP port 1900.

EPSS: 19.13%
5.0 CVSS
CVE-2005-4723
Exploit Found

D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.

EPSS: 3.23%