This page lists publicly disclosed CVE vulnerabilities affecting dlink dir-859_a3_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-57045 | A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page. | [email protected] | 9.8 | 32.26% | 2025-02-18 | 2026-06-17 |
| CVE-2022-25106 | D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. | [email protected] | 5.5 | 8.59% | 2022-03-04 | 2026-06-17 |
| CVE-2019-17508 | On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable. | [email protected] | 9.8 | 15.84% | 2019-10-11 | 2026-06-16 |