Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Di\-7003g_firmware
(Dlink)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 21 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2025-05-19 | CVE-2025-4901 | A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. | Di\-7003g_firmware | 6.5 | ||
2025-05-19 | CVE-2025-4902 | A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this issue is the function sub_48F4F0 of the file /H5/versionupdate.data. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | Di\-7003g_firmware | 7.5 | ||
2023-10-16 | CVE-2023-45572 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the tgfile.htm function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45574 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the file.data function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45573 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the n parameter of the mrclfile_del.asp function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45575 | Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip parameter of the ip_position.asp function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45576 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the remove_ext_proto/remove_ext_port parameter of the upnp_ctrl.asp function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45577 | Stack Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the wanid parameter of the H5/speedlimit.data function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45578 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the pap_en/chap_en parameter of the pppoe_base.asp function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 | ||
2023-10-16 | CVE-2023-45579 | Buffer Overflow vulnerability in D-Link device DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the ip/type parameter of the jingx.asp function. | Di\-7003g_firmware, Di\-7100g\+_firmware, Di\-7100g_firmware, Di\-7200g\+_firmware, Di\-7200g_firmware, Di\-7300g\+_firmware, Di\-7400g\+_firmware | 9.8 |