d-link dir-615 Security Vulnerabilities

5 Vulnerabilities
Description

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2021-37388, Last Modified: 2021-08-06T12:43:00Z

References

Advisory

The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2019-17525, Last Modified: 2020-04-21T19:21:00Z

References

Advisory

On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2019-19742, Last Modified: 2019-12-18T13:26:00Z

References

Advisory

On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

Impacted versions: -

Base Score: 0.0, Severity: NA, ID: CVE-2019-19743, Last Modified: 2019-12-16T18:33:00Z

References

Advisory

The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified vectors, or (3) modify DNS settings via unspecified vectors.

Impacted versions: 3.10na

Base Score: 5.0, Severity: MEDIUM, ID: CVE-2009-4821, Last Modified: 2010-04-28T04:00:00Z

References

Vendor Advisory Exploit

Modemly Security Checklist

Dlink-DIR-615-router-setup
Free Home-Networking Courses, tutorials and security checklists

USAGE: Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.