Dir X3260
Vendor:
First CVE: May 2, 2024 · Active for 2 years
23
Total CVEs
More Total CVEs than 95% of tracked products
23.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dir X3260 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2024
2 years ago
Most Recent CVE
May 3, 2024
815 days ago
CVE Severity & Scoring
Dir X326023 CVEs
48%
52%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network23 (100.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (34.8%)
High11 (47.8%)
None4 (17.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44420HIGH D-Link DIR-X3260 prog.cgi Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass a | May 3, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-44419HIGH D-Link DIR-X3260 Prog.cgi Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affecte | May 3, 2024 | 8.8 | 26 | NO | NO |
CVE-2023-44427HIGH D-Link DIR-X3260 SetSysEmailSettings SMTPServerAddress Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitr | May 3, 2024 | 8.0 | 25 | NO | NO |
CVE-2023-44424HIGH D-Link DIR-X3260 SetSysEmailSettings EmailTo Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code o | May 3, 2024 | 8.0 | 25 | NO | NO |
CVE-2023-44422HIGH D-Link DIR-X3260 SetSysEmailSettings EmailFrom Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code | May 3, 2024 | 8.0 | 25 | NO | NO |
CVE-2023-44426HIGH D-Link DIR-X3260 SetSysEmailSettings AccountPassword Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrar | May 3, 2024 | 8.0 | 24 | NO | NO |
CVE-2023-44425HIGH D-Link DIR-X3260 SetSysEmailSettings AccountName Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary co | May 3, 2024 | 8.0 | 24 | NO | NO |
CVE-2023-44423HIGH D-Link DIR-X3260 SetTriggerPPPoEValidate Password Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary c | May 3, 2024 | 8.0 | 24 | NO | NO |
CVE-2023-44421HIGH D-Link DIR-X3260 SetTriggerPPPoEValidate Username Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary c | May 3, 2024 | 8.0 | 24 | NO | NO |
CVE-2023-44418HIGH D-Link DIR-X3260 Prog.cgi Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected | May 3, 2024 | 8.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Dir X3260
Top CWEs
Versions
No cataloged versions.