📦

dir-100

Vendor: d-link

Actively Exploited 0 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 8.85% Exploit Prob.
Latest CVE CVE-2013-7055 Feb 04

Security Vulnerability Index

Page 1 / 1
9.8 CVSS
CVE-2013-7055
Exploit Found

D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

EPSS: 6.98%
6.1 CVSS
CVE-2013-7054
Exploit Found

D-Link DIR-100 4.03B07: cli.cgi XSS

EPSS: 3.50%
8.8 CVSS
CVE-2013-7053
Exploit Found

D-Link DIR-100 4.03B07: cli.cgi CSRF

EPSS: 3.38%
9.8 CVSS
CVE-2013-7052
Exploit Found

D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

EPSS: 24.68%
8.8 CVSS
CVE-2013-7051
Exploit Found

D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

EPSS: 15.61%
8.5 CVSS
CVE-2013-6027
Exploit Found

Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/tools_misc.xgi.

EPSS: 4.69%
10.0 CVSS

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.

EPSS: 7.68%
4.3 CVSS
CVE-2008-4133
Exploit Found

The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters.

EPSS: 4.25%