D Link
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any D Link product.
RSS Feeds for D Link security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in D Link products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by D Link Sorted by Most Security Vulnerabilities since 2018
Known Exploited D Link Vulnerabilities
The following D Link vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| D-Link DIR-823X Command Injection Vulnerability |
D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2025-29635 Exploit Probability: 87.9% |
April 24, 2026 |
| D-Link Routers Buffer Overflow Vulnerability |
D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2022-37055 Exploit Probability: 55.5% |
December 8, 2025 |
| D-Link DNR-322L Download of Code Without Integrity Check Vulnerability |
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2022-40799 Exploit Probability: 33.7% |
August 5, 2025 |
| D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability |
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2020-25079 Exploit Probability: 54.0% |
August 5, 2025 |
| D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability |
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. CVE-2020-25078 Exploit Probability: 97.5% |
August 5, 2025 |
| D-Link DIR-859 Router Path Traversal Vulnerability |
D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS CVE-2024-0769 Exploit Probability: 82.7% |
June 25, 2025 |
| D-Link DIR-820 Router OS Command Injection Vulnerability |
D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. CVE-2023-25280 Exploit Probability: 97.9% |
September 30, 2024 |
| D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability |
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. CVE-2014-100005 Exploit Probability: 43.5% |
May 16, 2024 |
| D-Link DIR-605 Router Information Disclosure Vulnerability |
D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. CVE-2021-40655 Exploit Probability: 86.7% |
May 16, 2024 |
| D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability |
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. CVE-2024-3272 Exploit Probability: 98.0% |
April 11, 2024 |
| D-Link Multiple NAS Devices Command Injection Vulnerability |
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. CVE-2024-3273 Exploit Probability: 100.0% |
April 11, 2024 |
| D-Link DSL-2750B Devices Command Injection Vulnerability |
D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. CVE-2016-20017 Exploit Probability: 64.2% |
January 8, 2024 |
| D-Link DIR-859 Router Command Execution Vulnerability |
D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. CVE-2019-17621 Exploit Probability: 89.6% |
June 29, 2023 |
| D-Link DWL-2600AP Access Point Command Injection Vulnerability |
D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. CVE-2019-20500 Exploit Probability: 96.7% |
June 29, 2023 |
| D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability |
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information. CVE-2011-4723 Exploit Probability: 3.1% |
September 8, 2022 |
| D-Link Multiple Routers OS Command Injection Vulnerability |
Multiple D-Link routers contain an unspecified vulnerability which allows for execution of OS commands. CVE-2018-6530 Exploit Probability: 96.7% |
September 8, 2022 |
| D-Link DIR-820L Remote Code Execution Vulnerability |
D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. CVE-2022-26258 Exploit Probability: 91.6% |
September 8, 2022 |
| D-Link DIR-816L Remote Code Execution Vulnerability |
D-Link DIR-816L contains an unspecified vulnerability in the shareport.php value parameter which allows for remote code execution. CVE-2022-28958 |
September 8, 2022 |
| D-Link DNS-320 Remote Code Execution Vulnerability |
The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution. CVE-2019-16057 Exploit Probability: 86.5% |
April 15, 2022 |
| D-Link Multiple Routers Remote Code Execution Vulnerability |
A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file. CVE-2021-45382 Exploit Probability: 97.8% |
April 4, 2022 |
Of the known exploited vulnerabilities above, 15 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 3 known exploited D Link vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest D Link Vulnerabilities
Based on the current exploit probability, these D Link vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2024-3273 | 100.0% | D-Link Multiple NAS Devices Command Injection Vulnerability |
| 2 | CVE-2019-16920 | 100.0% | D-Link Multiple Routers Command Injection Vulnerability |
| 3 | CVE-2020-25506 | 100.0% | D-Link DNS-320 Command Injection Remote Code Execution Vulnerability |
| 4 | CVE-2024-3272 | 98.0% | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability |
| 5 | CVE-2023-25280 | 97.9% | D-Link DIR-820 Router OS Command Injection Vulnerability |
| 6 | CVE-2021-45382 | 97.8% | D-Link Multiple Routers Remote Code Execution Vulnerability |
| 7 | CVE-2020-25078 | 97.5% | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability |
| 8 | CVE-2015-2051 | 97.1% | D-Link DIR-645 Router Remote Code Execution Vulnerability |
| 9 | CVE-2019-20500 | 96.7% | D-Link DWL-2600AP Access Point Command Injection Vulnerability |
| 10 | CVE-2018-6530 | 96.7% | D-Link Multiple Routers OS Command Injection Vulnerability |
By the Year
In 2026 there have been 58 vulnerabilities in D Link with an average score of 7.7 out of ten. Last year, in 2025 D Link had 8 security vulnerabilities published. That is, 50 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.43.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 58 | 7.73 |
| 2025 | 8 | 6.30 |
| 2024 | 1 | 0.00 |
| 2023 | 5 | 0.00 |
| 2022 | 2 | 9.80 |
| 2021 | 1 | 9.80 |
| 2020 | 1 | 0.00 |
| 2019 | 2 | 0.00 |
| 2018 | 6 | 7.70 |
It may take a day or so for new D Link vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent D Link Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-96891 | Sep 24, 2026 |
D-Link DIR-825 3.00b32 rp-l2tp tunnel_set_params OOB Write via peer_hostnameA vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely. |
|
| CVE-2026-94089 | Sep 20, 2026 |
DIR-868L 2.01b05 Auth Handler Stack Buffer Overflow via strcpyA vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-94050 | Sep 20, 2026 |
D-Link DIR-X1860Z ubus JSON-RPC Info Disclosure (pre-1.0.7)A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure. The attack must be carried out from within the local network. Upgrading to version 1.0.7.260821.161908 is able to address this issue. It is suggested to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer. |
|
| CVE-2026-94036 | Sep 20, 2026 |
D-Link DIR-X1860 routerd/ubus passwd_set access control flaw <=1.0.2.220120.165402A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-93958 | Sep 20, 2026 |
D-Link R95 1.00.16 OS Cmd Injection via /bin/ssi (NTPServer)A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-91003 | Sep 15, 2026 |
Stack-based buffer overflow in D-Link DI8300 16.07 CGI svc (rzgl_asp)A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
|
| CVE-2026-91001 | Sep 15, 2026 |
Stack Buffer Overflow in D-Link DI-8400 16.07 DDNS ddns_aspA security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-90881 | Sep 15, 2026 |
DIR-882 CGI Binary Info Disclosure via dllog.cgiA weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-90880 | Sep 15, 2026 |
D-Link DSL-3782 CGI Diagnostic Cmd InjectionA security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-90706 | Sep 14, 2026 |
D-Link DWR-M921 1.1.52 OS Command Injection via formWsc TargetAPSsidA vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-90705 | Sep 14, 2026 |
D-Link DWR-M921 1.1.52 FormsysCmd OS cmd injection via sysCmdA vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-90704 | Sep 14, 2026 |
D-Link DWR-M921 1.1.52 Command Injection via devicename /boafrm/formDiskPartitionA vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-90703 | Sep 14, 2026 |
D-Link DWR-M921 1.1.52 OS Command Injection via formDiskCreateShareA vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-90702 | Sep 14, 2026 |
Command Injection via /boafrm/formDiskFormat in D-Link DWR-M921 1.1.52 Remote ExploitA flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-90699 | Sep 14, 2026 |
D-Link DWR-M920 1.1.7 Command Injection in formPinManageSetupA weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-90693 | Sep 14, 2026 |
D-Link DIR-878 SetWan3Settings Buffer Overflow via Primary/Secondary manipulationA flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the attack is possible. |
|
| CVE-2026-90692 | Sep 14, 2026 |
Stack Buffer Overflow in D-Link DIR-878 Dynamic DNS IPv6 SettingsA vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched remotely. |
|
| CVE-2026-90680 | Sep 14, 2026 |
Stack Overflow in D-Link DIR-823G 1.0.2B05 HNAP1 strcpyA security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely. |
|
| CVE-2026-86510 | Sep 08, 2026 |
OOB Write in D-Link DIR-822A L2TP Parser via tunnel_set_paramsA vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86509 | Sep 08, 2026 |
Stack buffer overflow in D-Link DIR-895L udhcpcd sendOffer/sendACKA flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used. |
|
| CVE-2026-86297 | Sep 07, 2026 |
D-Link DIR-605 L2TP Off-by-One via peer_hostnameA vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used. |
|
| CVE-2026-86296 | Sep 07, 2026 |
DIR-822A udhcpcd Stack BOverflow via strcpyA vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-86295 | Sep 07, 2026 |
CVE-2026-86295: D-Link DIR-895L Remote Command Injection via udhcpcd sendACKA vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-85224 | Sep 03, 2026 |
D-Link DNS-320 v2.06B01 File Sharing CGI OS Command Injection via fileurlA vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-85223 | Sep 03, 2026 |
D-Link DNS-340L 1.01B04 Remote OS Command Injection via CGI HandlerA vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-85222 | Sep 03, 2026 |
D-Link DNS340L 1.01B04 AddOn Center CGI OS Command Injection RemoteA vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-82692 | Aug 31, 2026 |
D-Link DNS-340L/DNS-345 OS Command Injection via iscsi_mgr.cgiA vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-82691 | Aug 31, 2026 |
OS Command Injection via usb_device CGI on D-Link DNS-32xL SeriesA vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. |
And others... |
| CVE-2026-82690 | Aug 31, 2026 |
D-Link DNS-327L/DNS-340L: os Command Injection via CGI Argument f_dev (remote)A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. |
|
| CVE-2026-82689 | Aug 31, 2026 |
D-Link DNS Router OS Command Injection via ISO Image Handler (CVE-2026-82689)A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. |
And others... |
| CVE-2026-82688 | Aug 31, 2026 |
D-Link DNS-340L/345 OS command injection via Virtual Volume Handler before 1.05b04A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-82680 | Aug 31, 2026 |
D-Link DSM-G600 1.01 OOB Write via Multipart Handler in /load_file.cgiA weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-82595 | Aug 30, 2026 |
DIR-825M 1.1.8 Remote Command Injection via sysCmd (sub_456CF4)A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-82593 | Aug 30, 2026 |
Remote Stack Buffer Overflow in D-Link DIR-825M 1.1.8 LTE Module Firmware UpgradeA flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. |
|
| CVE-2026-82592 | Aug 30, 2026 |
D-Link DIR-825M 1.1.8 stack-buffer overflow in Disk Format HandlerA vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. |
|
| CVE-2026-19893 | Aug 15, 2026 |
DIR-842 2.01.B04 vsftpd: Incorrect default perms via /etc/vsftpd.conf (remote)A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. |
|
| CVE-2026-16448 | Jul 21, 2026 |
D-Link DNS- series cmdinject in remote_backup.cgiA vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. |
And others... |
| CVE-2026-16447 | Jul 21, 2026 |
Unrestricted Upload via Filedata[] in D-Link DNS-320 1.0.2 (multi_uploadify.php)A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-16332 | Jul 21, 2026 |
Unrestricted File Upload in D-Link DNS-320 1.0.2 via multi_uploadify.phpA vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
|
| CVE-2026-16331 | Jul 21, 2026 |
Unrestricted Upload in D-Link DNS-320 1.0.2 /save_ajax.phpA security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-16330 | Jul 21, 2026 |
D-Link DNS320 1.0.2: Unrestricted File Upload via uploadify.phpA weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-16329 | Jul 21, 2026 |
D-Link DNS-320 1.0.2 Unrestricted File Upload via uploadify.phpA vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-16327 | Jul 20, 2026 |
D-Link DNS-320 1.0.2 Remote Unrestricted File Upload via /web/web_file/upload.phpA vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-15270 | Jul 09, 2026 |
Least Privilege Violation in D-Link DIR-823G (1.0.2B05) via /etc/boa/boa.confA weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-13545 | Jun 29, 2026 |
Command Injection in D-Link DCS-935L 1.10.01 POST Handler (before v1.10.02)A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-12174 | Jun 13, 2026 |
D-Link DCS-935L 1.10.01 fmtstr via snprintf in HTTP HandlerA security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-11555 | Jun 08, 2026 |
D-Link DGS-1100-08PD 1.00.006 WebInterface /etc/boa.conf LVPA vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used. |
|
| CVE-2026-11497 | Jun 08, 2026 |
Least Privilege Violation via Boa Webserver in D-Link DCS-5615 v1.01.00A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-11492 | Jun 08, 2026 |
Least Privilege Violation in vsftpd of D-Link DIR-823G 1.0.2B05A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-11341 | Jun 05, 2026 |
Command Injection in D-Link DWR-M920 (<=1.1.50) via IMEI_setupA flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|