D-Link Vulnerabilities
D-Link produces consumer and business networking gear such as Wi-Fi routers, IP cameras and switches, and its announcement page also flags end-of-life models that no longer receive fixes. The database tracks 61 D-Link CVE records. CISA lists 27 of them as exploited in the wild, most recently on 2026-04-24. The most affected products are DNS-120, DIR-823X, DIR-615.
Recently Exploited D-Link CVEs
D-Link DIR-823X Command Injection Vulnerability
D-Link Routers Buffer Overflow Vulnerability
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal
Affected Products
33 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| DNS-120 | 10 | - | 2026-03-16 |
| DIR-823X | 9 | 1 | 2026-04-24 |
| DIR-615 | 5 | - | 2026-02-08 |
| Multiple Routers | 3 | 3 | 2022-09-08 |
| DCS-2530L and DCS-2670L Devices | 2 | 2 | 2025-08-05 |
| DCS-931L | 2 | - | 2026-02-10 |
| DIR-859 Router | 2 | 2 | 2025-06-25 |
| DNS-320 | 2 | - | 2026-05-11 |
| Multiple NAS Devices | 2 | 2 | 2024-04-11 |
| DCS-930L Devices | 1 | 1 | 2022-03-25 |
| DCS-935L | 1 | - | 2026-06-29 |
| DCS700l | 1 | - | 2026-01-26 |
| DI-8200G | 1 | - | 2026-01-08 |
| DIR-300 Router | 1 | 1 | 2022-09-08 |
| DIR-600 | 1 | - | 2026-02-08 |
| DIR-600 Router | 1 | 1 | 2024-05-16 |
| DIR-605 Router | 1 | 1 | 2024-05-16 |
| DIR-610 Devices | 1 | 1 | 2022-03-25 |
| DIR-645 Router | 1 | 1 | 2022-02-10 |
| DIR-820 Router | 1 | 1 | 2024-09-30 |
| DIR-820L | 1 | 1 | 2022-09-08 |
| DIR-825 R1 Devices | 1 | 1 | 2021-11-03 |
| DIR-868L | 1 | - | 2026-03-03 |
| DIR-882 | 1 | - | 2026-04-09 |
| DNR-322L | 1 | 1 | 2025-08-05 |
| DNS-320 Device | 1 | 1 | 2021-11-03 |
| DNS-320 Storage Device | 1 | 1 | 2022-04-15 |
| DSL-2750B Devices | 1 | 1 | 2024-01-08 |
| DSL-2760U | 1 | 1 | 2022-03-25 |
| DWL-2600AP Access Point | 1 | 1 | 2023-06-29 |
| DWR-M921 | 1 | - | 2026-02-07 |
| Multiple Devices | 1 | 1 | 2022-03-25 |
| Routers | 1 | 1 | 2025-12-08 |
All D-Link CVEs
61 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2025-29635 | D-Link DIR-823X Command Injection Vulnerability | - | 7.2 | 87.9% | KEV | 2025-03-25 |
| CVE-2022-37055 | D-Link Routers Buffer Overflow Vulnerability | - | 9.8 | 55.5% | KEV | 2022-08-28 |
| CVE-2020-25078 | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability | - | 7.5 | 97.5% | KEV | 2020-09-02 |
| CVE-2020-25079 | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | - | 8.8 | 54.0% | KEV | 2020-09-02 |
| CVE-2022-40799 | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | - | 8.8 | 33.7% | KEV | 2022-11-29 |
| CVE-2024-0769 | D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal | D-Link | 5.3 | 82.7% | KEV | 2024-01-21 |
| CVE-2023-25280 | D-Link DIR-820 Router OS Command Injection Vulnerability | - | 9.8 | 97.9% | KEV | 2023-03-16 |
| CVE-2021-40655 | D-Link DIR-605 Router Information Disclosure Vulnerability | - | 7.5 | 86.7% | KEV | 2021-09-24 |
| CVE-2014-100005 | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | - | 8.0 | 43.5% | KEV | 2015-01-13 |
| CVE-2024-3273 | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection | D-Link | 7.5 | 100.0% | KEV | 2024-04-04 |
| CVE-2024-3272 | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials | D-Link | 10.0 | 98.0% | KEV | 2024-04-04 |
| CVE-2016-20017 | D-Link DSL-2750B Devices Command Injection Vulnerability | - | 9.8 | 64.2% | KEV | 2022-10-19 |
| CVE-2019-20500 | D-Link DWL-2600AP Access Point Command Injection Vulnerability | - | 7.8 | 96.7% | KEV | 2020-03-05 |
| CVE-2019-17621 | D-Link DIR-859 Router Command Execution Vulnerability | - | 9.8 | 89.6% | KEV | 2019-12-30 |
| CVE-2018-6530 | D-Link Multiple Routers OS Command Injection Vulnerability | - | 9.8 | 96.7% | KEV | 2018-03-06 |
| CVE-2022-26258 | D-Link DIR-820L Remote Code Execution Vulnerability | - | 9.8 | 92.0% | KEV | 2022-03-27 |
| CVE-2011-4723 | D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability | - | 5.7 | 3.1% | KEV | 2011-12-20 |
| CVE-2019-16057 | D-Link DNS-320 Remote Code Execution Vulnerability | - | 9.8 | 86.5% | KEV | 2019-09-16 |
| CVE-2021-45382 | D-Link Multiple Routers Remote Code Execution Vulnerability | - | 9.8 | 97.8% | KEV | 2022-02-17 |
| CVE-2019-16920 | D-Link Multiple Routers Command Injection Vulnerability | - | 9.8 | 100.0% | KEV | 2019-09-27 |
| CVE-2015-1187 | D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability | - | 9.8 | 82.9% | KEV | 2017-09-21 |
| CVE-2016-11021 | D-Link DCS-930L Devices OS Command Injection Vulnerability | - | 7.2 | 68.9% | KEV | 2020-03-09 |
| CVE-2013-5223 | D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability | - | 5.4 | 50.8% | KEV | 2013-11-15 |
| CVE-2020-9377 | D-Link DIR-610 Devices Remote Command Execution | - | 8.8 | 21.3% | KEV | 2020-07-09 |
| CVE-2015-2051 | D-Link DIR-645 Router Remote Code Execution Vulnerability | - | 8.8 | 97.1% | KEV | 2015-02-23 |
| CVE-2020-25506 | D-Link DNS-320 Device Command Injection Vulnerability | - | 9.8 | 100.0% | KEV | 2021-02-02 |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability | - | 9.8 | 54.3% | KEV | 2021-01-29 |
| CVE-2026-4197 | D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection | D-Link | 6.5 | 23.7% | 2026-03-15 | |
| CVE-2026-1419 | D-Link DCS700l Web Form setDayNightMode command injection | D-Link | 5.8 | 17.2% | 2026-01-26 | |
| CVE-2026-1125 | D-Link DIR-823X set_wifidog_settings sub_412E7C command injection | D-Link | 7.5 | 15.7% | 2026-01-18 | |
| CVE-2026-0732 | D-Link DI-8200G upgrade_filter.asp command injection | D-Link | 6.5 | 11.7% | 2026-01-08 | |
| CVE-2026-2227 | D-Link DCS-931L setSystemAdmin doSystem command injection | D-Link | 5.8 | 6.8% | 2026-02-09 | |
| CVE-2026-3485 | D-Link DIR-868L SSDP Service sub_1BF84 os command injection | D-Link | 10.0 | 6.7% | 2026-03-03 | |
| CVE-2026-2142 | D-Link DIR-823X set_qos sub_420688 os command injection | D-Link | 8.6 | 6.6% | 2026-02-08 | |
| CVE-2026-2163 | D-Link DIR-600 ssdp.cgi command injection | D-Link | 5.8 | 6.6% | 2026-02-08 | |
| CVE-2026-2081 | D-Link DIR-823X set_password os command injection | D-Link | 5.8 | 6.4% | 2026-02-07 | |
| CVE-2026-5844 | D-Link DIR-882 HNAP1 SetNetworkSettings prog.cgi sprintf os command injection | D-Link | 8.6 | 6.2% | 2026-04-09 | |
| CVE-2026-4203 | D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection | D-Link | 6.5 | 6.1% | 2026-03-16 | |
| CVE-2026-8271 | D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection | D-Link | 5.8 | 6.1% | 2026-05-11 | |
| CVE-2026-8272 | D-Link DNS-320 webfile_mgr.cgi chown os command injection | D-Link | 5.8 | 6.0% | 2026-05-11 | |
| CVE-2026-2082 | D-Link DIR-823X set_mac_clone os command injection | D-Link | 5.8 | 5.9% | 2026-02-07 | |
| CVE-2026-2260 | D-Link DCS-931L setSysAdmin os command injection | D-Link | 8.6 | 5.8% | 2026-02-10 | |
| CVE-2026-1448 | D-Link DIR-615 Web Management wiz_policy_3_machine.php os command injection | D-Link | 8.6 | 5.8% | 2026-01-26 | |
| CVE-2026-4209 | D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-4196 | D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection | D-Link | 6.5 | 5.8% | 2026-03-15 | |
| CVE-2026-4207 | D-Link DNS-1550-04 system_mgr.cgi cgi_ntp_time command injection | D-Link | 6.5 | 5.8% | 2026-03-16 | |
| CVE-2026-1506 | D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection | D-Link | 8.6 | 5.6% | 2026-01-28 | |
| CVE-2026-13545 | D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection | D-Link | 9.0 | 5.5% | 2026-06-29 | |
| CVE-2026-4195 | D-Link DNS-1550-04 wizard_mgr.cgi command injection | D-Link | 6.5 | 5.5% | 2026-03-15 | |
| CVE-2026-4204 | D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-4210 | D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection | D-Link | 6.5 | 5.5% | 2026-03-16 | |
| CVE-2026-2152 | D-Link DIR-615 Web Configuration adv_routing.php os command injection | D-Link | 8.6 | 5.4% | 2026-02-08 | |
| CVE-2026-2151 | D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection | D-Link | 8.6 | 5.3% | 2026-02-08 | |
| CVE-2026-2063 | D-Link DIR-823X Web Management set_ac_server os command injection | D-Link | 5.8 | 5.3% | 2026-02-06 | |
| CVE-2026-2085 | D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection | D-Link | 8.6 | 5.2% | 2026-02-07 | |
| CVE-2026-2061 | D-Link DIR-823X set_ipv6 sub_424D20 os command injection | D-Link | 5.8 | 5.1% | 2026-02-06 | |
| CVE-2026-4205 | D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-4206 | D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection | D-Link | 6.5 | 5.1% | 2026-03-16 | |
| CVE-2026-1505 | D-Link DIR-615 URL Filter set_temp_nodes.php os command injection | D-Link | 8.6 | 5.1% | 2026-01-28 | |
| CVE-2026-2129 | D-Link DIR-823X set_ac_status os command injection | D-Link | 8.6 | 5.0% | 2026-02-08 | |
| CVE-2026-2143 | D-Link DIR-823X DDNS Service set_ddns os command injection | D-Link | 8.6 | 5.0% | 2026-02-08 |
Frequently Asked Questions
How many D-Link vulnerabilities are actively exploited?→
27 D-Link CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-04-24.
Which D-Link vulnerabilities are used in ransomware attacks?→
CISA marks 2 D-Link KEV entries as known to be used in ransomware campaigns, including CVE-2018-6530, CVE-2019-16057.
Which D-Link products have the most exploited vulnerabilities?→
- +DNS-120: 10 CVEs (0 in KEV)
- +DIR-823X: 9 CVEs (1 in KEV)
- +DIR-615: 5 CVEs (0 in KEV)
- +Multiple Routers: 3 CVEs (3 in KEV)
- +DCS-2530L and DCS-2670L Devices: 2 CVEs (2 in KEV)
Where does D-Link publish security advisories?→
D-Link publishes security advisories at https://supportannouncement.us.dlink.com/. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by D-Link, MITRE, CISA, or FIRST.