D-Link vendor intelligence
D-Link Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting D-Link products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 50
- Known exploited vulnerabilities affecting D-Link products
- In CISA KEV
- 27
- Records also listed in the official catalog
- Beyond CISA KEV
- 23
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 2
- D-Link KEVs with sensor-observed exploitation activity
The catalog gap matters for D-Link exposure
23 of the 50 exploited D-Link CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 46% of this vendor portfolio.
- 54%
- Covered by CISA
- 46%
- Beyond CISA
- 46
- Product families
Attested D-Link CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-1125
D-Link DIR-823X set_wifidog_settings sub_412E7C command injection |
DIR-823X | High | Beyond CISA | 02 Jul 2026 |
|
CVE-2025-34048
D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read |
DSL-2730U, DSL-2750U, DSL-2750E | High | Beyond CISA | 24 May 2026 |
|
CVE-2021-46381
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. |
DAP-1620 | High | Beyond CISA | 31 Mar 2026 |
|
CVE-2023-4542
D-Link DAR-8000-10 sys1.php os command injection |
DAR-8000-10 | High | Beyond CISA | 19 Mar 2026 |
|
CVE-2021-3708
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local... |
DSL-2750U | High | Beyond CISA | 16 Jan 2026 |
|
CVE-2023-5074
Authentication Bypass in D-Link D-View 8 |
D-View 8 | High | Beyond CISA | 17 Dec 2025 |
|
CVE-2019-13372
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary... |
Central WiFi Manager CWM(100) | High | Beyond CISA | 28 Sep 2025 |
|
CVE-2020-24581
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not... |
DSL-2888A | High | Beyond CISA | 01 Oct 2025 |
|
CVE-2019-13101
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can... |
DIR-600M | High | Beyond CISA | 16 Sep 2025 |
|
CVE-2023-5148
D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload |
DAR-7000, DAR-8000 | High | Beyond CISA | 26 Jun 2025 |
|
CVE-2025-29635
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote... |
DIR-823X | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-0625
D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint |
DSL-2640B, DSL-2740R, DSL-2780B, DSL-526B, DSL-2640T, DSL-500, DSL-500G, DSL-502G, DIR-905L, DIR-600, DIR-608, DIR-610, DIR-611, DIR-615, DNS-320, DNS-325, DNS-345 | High | Beyond CISA | 01 Jun 2026 |
|
CVE-2022-37055
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, |
Go-RT-AC750 | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-40799
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the... |
DNR-322L | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-25079
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated... |
DCS-2530L, DCS-2670L | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-25078
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint... |
DCS-2530L, DCS-2670L | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-0769
D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal |
DIR-859 | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test |
DNS-343 ShareCenter | High | Beyond CISA | 29 Oct 2025 |
|
CVE-2025-5571
D-Link DCS-932L setSystemAdmin os command injection |
DCS-932L | High | Beyond CISA | 04 Jun 2025 |
|
CVE-2013-6026
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and... |
["DIR-100", "DIR-120", "DI-624S", "DI-524UP", "DI-604S", "DI-604UP", "DI-604+", "TM-G5240", "BRL-04R", "BRL-04UR", "BRL-04CW"] | High | Beyond CISA | 19 Oct 2013 |
|
CVE-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection |
DNS-320, DNS-320LW, DNS-325, DNS-340L | High | Beyond CISA | 24 Apr 2025 |
|
CVE-2019-17506
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the... |
DIR-868L, DIR-817LW | High | Beyond CISA | 27 Apr 2025 |
|
CVE-2020-25506
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code... |
DNS-320 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-29557
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to... |
DIR-825 R1 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2015-2051
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a... |
DIR-645 Wired/Wireless Router | Confirmed | In CISA | 10 Feb 2022 |
|
CVE-2013-5223
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web... |
DSL-2760U Gateway | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2015-1187
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. |
multiple devices | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-11021
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. |
DCS-930L | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-16920
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the... |
DIR-655C, DIR-866L, DIR-652, DHP-1565, DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, DIR-825 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2020-9377
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are... |
DIR-610 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2021-45382
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L... |
DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, DIR-836L routers | Confirmed | In CISA | 04 Apr 2022 |
|
CVE-2019-16057
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. |
DNS-320 | Confirmed | In CISA | 15 Apr 2022 |
|
CVE-2011-4723
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified... |
DIR-300 | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2018-6530
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous... |
DIR-880L, DIR-868L, DIR-865L, DIR-860L | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2022-26258
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. |
DIR-820L | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2019-20500
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the... |
DWL-2600AP | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2019-17621
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute... |
DIR-859 Wi-Fi router | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2016-20017
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in... |
DSL-2750B | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2024-3272
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials |
DNS-320L, DNS-325, DNS-327L, DNS-340L | Confirmed | In CISA | 11 Apr 2024 |
|
CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection |
DNS-320L, DNS-325, DNS-327L, DNS-340L | Confirmed | In CISA | 11 Apr 2024 |
|
CVE-2014-100005
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers... |
DIR-600 router | Confirmed | In CISA | 16 May 2024 |
|
CVE-2021-40655
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a... |
DIR-605 B2 Firmware | Confirmed | In CISA | 16 May 2024 |
|
CVE-2023-25280
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the... |
DIR820LA1_FW105B03 | Confirmed | In CISA | 30 Sep 2024 |
|
CVE-2021-46442
In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such... |
DIR-825 G1 | High | Beyond CISA | 27 Apr 2022 |
|
CVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. |
DIR850 | High | Beyond CISA | 04 Mar 2022 |
|
CVE-2021-39509
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of... |
DIR-816 | High | Beyond CISA | 24 Aug 2021 |
|
CVE-2020-10215
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name... |
DIR-825 Rev.B 2.10 | High | Beyond CISA | 07 Mar 2020 |
|
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635... |
DCS-3411/3430, DCS-5605/5635, DCS-1100L/1130L, DCS-1100/1130, DCS-2102/2121, DCS-3410, DCS-5230, DCS-6410, DCS-7410, DCS-7510, WCS-1100 | High | Beyond CISA | 28 Jan 2020 |
|
CVE-2018-15517
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually... |
Central WiFiManager CWM-100 | High | Beyond CISA | 31 Jan 2019 |
|
CVE-2018-10823
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and... |
DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, DWR-111 | High | Beyond CISA | 17 Oct 2018 |
No D-Link CVEs match this search or filter.
Showing 50 of 50 D-Link known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, neutralization, and missing authentication for critical function account for 31 mapped occurrences across this D-Link KEV portfolio.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-306
Missing Authentication for Critical Function
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-798
Use of Hard-coded Credentials
CWE-287
Improper Authentication
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-312
Cleartext Storage of Sensitive Information
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.