Home/Product/dlink central wifimanager
Product

dlink central wifimanager

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2019-13375
all versions
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the ind
9.8CRITICAL
CVE-2019-13374
all versions
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before
6.1MEDIUM
CVE-2019-13373
all versions
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbi
9.8CRITICAL
CVE-2019-13372
<= 1.03
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to e
9.8CRITICAL
CVE-2018-15517
all versions
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP serv
8.6HIGH
CVE-2018-15516
all versions
The FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce
5.8MEDIUM
CVE-2018-15515
all versions
The CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from th
7.8HIGH
CVE-2018-17443
>= 1.00 and <= 1.03
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoi
6.1MEDIUM
CVE-2018-17442
>= 1.00 and < 1.03
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the
8.8HIGH
CVE-2018-17441
>= 1.00 and <= 1.03
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint
6.1MEDIUM
CVE-2018-17440
>= 1.00 and < 1.03
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default
9.8CRITICAL
threatengine.sh