Vulnerabilities (CVE)

Filtered by vendor Dlink Subscribe
Filtered by product Dir-615 Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40654 1 Dlink 2 Dir-615, Dir-615 Firmware 2022-07-12 4.0 MEDIUM 6.5 MEDIUM
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
CVE-2019-19742 1 Dlink 2 Dir-615, Dir-615 Firmware 2021-04-23 3.5 LOW 4.8 MEDIUM
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
CVE-2018-15874 1 Dlink 2 Dir-615, Dir-615 Firmware 2021-04-23 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
CVE-2018-15875 1 Dlink 2 Dir-615, Dir-615 Firmware 2021-04-23 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.