CVE-2015-0151
https://notcve.org/view.php?id=CVE-2015-0151
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en dispositivos D-Link DIR-815, con firmware en versiones anteriores a la 2.07.B01, permite que atacantes remotos secuestren la autenticación de usuarios arbitrarios para peticiones que inserten secuencias XSS. • ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-815/REVB/DIR-815_REVB_FIRMWARE_PATCH_NOTES_2.07.B01_EN.PDF https://exchange.xforce.ibmcloud.com/vulnerabilities/110584 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2015-0153
https://notcve.org/view.php?id=CVE-2015-0153
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key. Los dispositivos D-Link DIR-815, con firmware en versiones anteriores a la 2.07.B01, permiten que atacantes remotos obtengan información sensible aprovechando el almacenamiento en texto claro de la clave inalámbrica. • ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-815/REVB/DIR-815_REVB_FIRMWARE_PATCH_NOTES_2.07.B01_EN.PDF https://exchange.xforce.ibmcloud.com/vulnerabilities/110586 • CWE-320: Key Management Errors •
CVE-2015-0152
https://notcve.org/view.php?id=CVE-2015-0152
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password. Los dispositivos D-Link DIR-815, con firmware en versiones anteriores a la 2.07.B01, permiten que atacantes remotos obtengan información sensible aprovechando el almacenamiento en texto claro de la contraseña administrativa. • ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-815/REVB/DIR-815_REVB_FIRMWARE_PATCH_NOTES_2.07.B01_EN.PDF https://exchange.xforce.ibmcloud.com/vulnerabilities/110585 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-8888
https://notcve.org/view.php?id=CVE-2014-8888
The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via vectors related to an "HTTP command injection issue." La interfaz de administración remota en dispositivos D-Link DIR-815, con firmware en versiones anteriores a la 2.03.B02, permite que atacantes remotos ejecuten comandos arbitrarios mediante vectores relacionados con un "HTTP command injection issue". • ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-815/REVB/DIR-815_REVB_FIRMWARE_PATCH_NOTES_2.03.B02_EN.PDF https://exchange.xforce.ibmcloud.com/vulnerabilities/110755 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •