These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A stack-based buffer overflow vulnerability exists in the D-Link DI-7001 MINI router firmware up to version 19.09.19A1. The vulnerability is located in the `sprintf` function within the `/httpd_debug.asp` file, a component of the device's API. Manipulation of the `Time` argument can trigger the overflow condition. The attack vector is network-based and the exploit has been publicly disclosed, increasing t [truncated]
CVE-2018-25358 documents an unauthenticated credential disclosure vulnerability in D-Link DIR-601 firmware version 2.02NA. The flaw resides in the /my_cgi.cgi endpoint, which accepts a table_name parameter that can be manipulated to extract sensitive configuration data without authentication. Affected parameters include admin_user, wireless_settings, and wireless_security, which return administrative cred [truncated]
CVE-2026-8260 is a HIGH severity vulnerability in the D-Link DCS-935L HNAP Service. The vulnerability is caused by a buffer overflow in the SetDeviceSettings function of the /web/cgi-bin/hnap/hnap_service file. The attack can be executed remotely and has been made public. This vulnerability has significant implications for users of the affected product, as it could allow an attacker to execute arbitrary c [truncated]
A buffer overflow vulnerability was found in D-Link DI-8100 16.07.26A1, affecting the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. This vulnerability has been publicly disclosed and may be used by attackers. The vulnerability has a high impact on the system and requires immediate attention. Users [truncated]
A buffer overflow vulnerability was found in D-Link DI-8100 16.07.26A1. The issue affects an unknown part of the file /url_member.asp of the Web Management Interface. Executing a manipulation of the argument Name can lead to buffer overflow. The attack can be launched remotely. Network administrators and security teams should review the CVE record and vendor guidance for affected scope and severity.
A buffer overflow vulnerability was detected in D-Link DI-8100 16.07.26A1, specifically in the tggl_asp function of the /tggl.asp file within the HTTP Request Handler component. The vulnerability is triggered by manipulating the Name argument, leading to a buffer overflow. This issue can be exploited remotely, potentially allowing attackers to execute arbitrary code or disrupt service. Network administrat [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T19:16:23.540Z and has not been modified since then. The NVD entry is currently Analyzed. This buffer overflow vulnerability in the url_rule_asp function of the /url_rule.asp file in D-Link DI-8100 16.07.26A1 can be exploited remotely through a POST parameter handler, posing a high severity risk w [truncated]
A weakness has been identified in D-Link DI-8100 16.07.26A1, specifically in the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes a buffer overflow, which can be exploited remotely. The exploit has been made available publicly and could be used for attacks. Users of D-Link DI-8100, especially those with exposure to the intern [truncated]
A stack-based buffer overflow vulnerability was identified in D-Link DI-8100 16.07.26A1, affecting the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to the vulnerability. The attack is possible to be carried out remotely. This CVE is of high severity with a CVSS score of 7.3. Network administrators and security teams should prioritize assessment and remediation efforts. [truncated]
CVE-2026-6947 is a HIGH severity (CVSS 8.7) authentication bypass vulnerability in the DWM-222W USB Wi-Fi Adapter developed by D-Link. The vulnerability allows unauthenticated adjacent network attackers to bypass brute-force protection mechanisms, enabling unlimited login attempts to gain unauthorized control over the device. The weakness is categorized as CWE-307 (Improper Restriction of Excessive Authen [truncated]
CVE-2025-29635 is a D-Link DIR-823X command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-04-24. Because it is listed in KEV, defenders should treat it as a high-priority remediation item and follow vendor mitigation guidance or discontinue use of the product if mitigations are unavailable.
A stack-based buffer overflow vulnerability exists in the hedwigcgi_main function of the /cgi-bin/hedwig.cgi file in D-Link DIR-645 versions 1.01, 1.02, and 1.03. This issue allows remote attackers to exploit the vulnerability. The exploit is now public and may be used. However, detailed information about the exploit and its impact is limited. The vulnerability only affects products that are no longer sup [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE record was published on 2026-04-08T19:24:17.913Z and has not been modified since then. Users of D-Link DI-8003 16.07.26A1 should assess and potentially apply vendor remediation.
CVE-2025-50671 is a HIGH severity vulnerability in D-Link DI-8003 16.07.26A1. The vulnerability exists due to improper handling of parameters in the /xwgl_ref.asp endpoint, allowing for a buffer overflow. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters. This vulnerability has a high CVSS score of 7.5, indicating a significant ris [truncated]
CVE-2025-50670 is a HIGH severity vulnerability in D-Link DI-8003 16.07.26A1. The vulnerability exists due to improper handling of parameters in the /xwgl_bwr.asp endpoint, allowing an attacker to exploit it by sending a crafted HTTP GET request. This could lead to potential code execution or denial of service. Users of D-Link DI-8003 16.07.26A1 should apply patches or mitigations to prevent exploitation. [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint. This HIGH severity vulnerability, with a CVSS score of 7.5, could allow attackers to execute arbitrary code or cause a denial of service. The CVE record was published on 2026-04-08T19:24:17.580Z and has not been modified since then. S [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue affects users of the D-Link DI-8003 16.07.26A1 product. The vulnerability allows for potential remote code execution. Users should review the official CVE record [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr. This issue has a CVSS score of 7.5 and is classified as HIGH severity. Security teams should review the official CVE and NVD records for detaile [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint. This HIGH severity vulnerability, with a CVSS score of 7.5, poses a significant risk to organizations using the affected device. The vulnerability's impact is primarily related to potential remote code execution or denial-of-service attacks. Security teams shou [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue affects users of the D-Link DI-8003 16.07.26A1 product. Users should review the official advisory and CVE record for affected scope and vendor guidance.
CVE-2025-50661 is a buffer overflow vulnerability in D-Link DI-8003 16.07.26A1. The vulnerability exists due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, en, ips, u, time, act, rpri, and log. This vulnerability has a high impact on affected systems, and security teams should [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint. This vulnerability has a high severity with a CVSS score of 7.5. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary precautions. The CVE record was published on 2026-04-08T19:24:16.583Z and has not been modified since t [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint. The CVE record was published on 2026-04-08T19:24:16.470Z and has not been modified since then. This vulnerability could allow an attacker to execute arbitrary code on the device, posing a significant risk to affected systems. Security teams should assess the [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue can lead to potential exploitation, allowing attackers to execute arbitrary code. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary pre [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint. This vulnerability could allow an attacker to execute arbitrary code on the device. The CVE record was published on 2026-04-08T19:24:16.257Z and has not been modified since then. Security teams should assess and mitigate this vulnerability to prevent potential attacks.
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue could allow an attacker to execute arbitrary code on the device. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary preca [truncated]
A HIGH severity vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the id parameter in the /saveparm_usb.asp endpoint. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The weakness is related to CWE-120. Security teams and administrators responsible for D-Link DI-8003 devices should be [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint. This HIGH severity vulnerability has a CVSS score of 7.5. It could allow for arbitrary code execution if exploited. Security teams and administrators should be aware of this vulnerability and take necessary actions to mitigate the risk. [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This vulnerability could allow an attacker to execute arbitrary code on the device. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take neces [truncated]
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. This issue may allow an attacker to execute arbitrary code. Affected users should apply patches or updates as recommended by the vendor. The vulnerability is caused by inadequate input validation in the /tggl. [truncated]