UNSUPPORTED WHEN ASSIGNED D-Link DIR-868L fwrevA1-12eumulti20170316 was discovered to contain a buffer overflow via the param2 parameter in the FUN0000acb4 function.
UNSUPPORTED WHEN ASSIGNED D-Link DIR-868L fwrevA1-12eumulti20170316 was discovered to contain a buffer overflow via the acStack50 parameter.
UNSUPPORTED WHEN ASSIGNED D-Link DIR-868L fwrevA1-12eumulti20170316 was discovered to contain a buffer overflow via the param2 parameter in the inetntoa() function.
UNSUPPORTED WHEN ASSIGNED D-Link DIR-868L Hardware version A1, firmware version 1.12 is vulnerable to Buffer Overflow. The vulnerability is in scandir.sgi binary.
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.
D-Link DIR-859 routers before v1.07b03beta allow Unauthenticated Information Disclosure via the AUTHORIZEDGROUP=1%0a value, as demonstrated by vpnconfig.php.
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folderview.php or categoryview.php.
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).
Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L, DIR-890L, DIR-885L, DIR-880L, DIR-868L, and DIR-850L.
CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.