D Link D Link

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any D Link product.

RSS Feeds for D Link security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in D Link products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by D Link Sorted by Most Security Vulnerabilities since 2018

D Link Dir 823x10 vulnerabilities

D Link Dns 340l8 vulnerabilities

D Link Dns 3207 vulnerabilities

D Link Dns 3455 vulnerabilities

D Link Dwr M9215 vulnerabilities

D Link Dwr M9204 vulnerabilities

D Link Dns 327l4 vulnerabilities

D Link Dns 320l3 vulnerabilities

D Link Di 7001 Mini3 vulnerabilities

D Link Di 7100g C13 vulnerabilities

D Link Dir 825m3 vulnerabilities

D Link Dir 823g3 vulnerabilities

D Link Dvg G5402sp Firmware2 vulnerabilities

D Link Dir X1860z2 vulnerabilities

D Link Dir 8782 vulnerabilities

D Link Dir 895l2 vulnerabilities

D Link Dir 822a2 vulnerabilities

D Link Dir 619l2 vulnerabilities

D Link Dir 3002 vulnerabilities

D Link Di 84002 vulnerabilities

D Link Dcs 935l2 vulnerabilities

D Link Dsl 2750u1 vulnerability

D Link Dns 320lw1 vulnerability

D Link Dns 3211 vulnerability

D Link Dns 3231 vulnerability

D Link Dns 3251 vulnerability

D Link Dns 3261 vulnerability

D Link Dgs 1100 08pd1 vulnerability

D Link Dns 3431 vulnerability

D Link Dns 726 41 vulnerability

D Link Dns 315l1 vulnerability

D Link Dsl 320b D11 vulnerability

D Link Dsl 37821 vulnerability

D Link Dsm G6001 vulnerability

D Link Dcs 56151 vulnerability

D Link Dcs 2750e1 vulnerability

D Link Dap 23101 vulnerability

D Link R951 vulnerability

D Link Dir 8521 vulnerability

D Link Dir 6001 vulnerability

D Link Dir 6051 vulnerability

D Link Dir 605l1 vulnerability

D Link Dir 6151 vulnerability

D Link Dir 8151 vulnerability

D Link Dir 8161 vulnerability

D Link Dir 816 A21 vulnerability

D Link Di 83001 vulnerability

D Link Di 82001 vulnerability

D Link Di 81001 vulnerability

D Link Dir 8251 vulnerability

D Link Di 80031 vulnerability

D Link Dir 8421 vulnerability

D Link Dir 868l1 vulnerability

D Link Dir 8821 vulnerability

D Link 202l1 vulnerability

D Link Dir X18601 vulnerability

D Link Dnr 202l1 vulnerability

D Link Dnr 322l1 vulnerability

D Link Dnr 3261 vulnerability

D Link Dns 1100 41 vulnerability

D Link Dns 1201 vulnerability

D Link Dns 1200 051 vulnerability

D Link Dns 1550 041 vulnerability

Known Exploited D Link Vulnerabilities

The following D Link vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
D-Link DIR-823X Command Injection Vulnerability D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2025-29635 Exploit Probability: 87.9%
April 24, 2026
D-Link Routers Buffer Overflow Vulnerability D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2022-37055 Exploit Probability: 55.5%
December 8, 2025
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2022-40799 Exploit Probability: 33.7%
August 5, 2025
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2020-25079 Exploit Probability: 54.0%
August 5, 2025
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
CVE-2020-25078 Exploit Probability: 97.5%
August 5, 2025
D-Link DIR-859 Router Path Traversal Vulnerability D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS
CVE-2024-0769 Exploit Probability: 82.7%
June 25, 2025
D-Link DIR-820 Router OS Command Injection Vulnerability D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
CVE-2023-25280 Exploit Probability: 97.9%
September 30, 2024
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
CVE-2014-100005 Exploit Probability: 43.5%
May 16, 2024
D-Link DIR-605 Router Information Disclosure Vulnerability D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
CVE-2021-40655 Exploit Probability: 86.7%
May 16, 2024
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.
CVE-2024-3272 Exploit Probability: 98.0%
April 11, 2024
D-Link Multiple NAS Devices Command Injection Vulnerability D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.
CVE-2024-3273 Exploit Probability: 100.0%
April 11, 2024
D-Link DSL-2750B Devices Command Injection Vulnerability D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.
CVE-2016-20017 Exploit Probability: 64.2%
January 8, 2024
D-Link DIR-859 Router Command Execution Vulnerability D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
CVE-2019-17621 Exploit Probability: 89.6%
June 29, 2023
D-Link DWL-2600AP Access Point Command Injection Vulnerability D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
CVE-2019-20500 Exploit Probability: 96.7%
June 29, 2023
D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.
CVE-2011-4723 Exploit Probability: 3.1%
September 8, 2022
D-Link Multiple Routers OS Command Injection Vulnerability Multiple D-Link routers contain an unspecified vulnerability which allows for execution of OS commands.
CVE-2018-6530 Exploit Probability: 96.7%
September 8, 2022
D-Link DIR-820L Remote Code Execution Vulnerability D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.
CVE-2022-26258 Exploit Probability: 91.6%
September 8, 2022
D-Link DIR-816L Remote Code Execution Vulnerability D-Link DIR-816L contains an unspecified vulnerability in the shareport.php value parameter which allows for remote code execution.
CVE-2022-28958
September 8, 2022
D-Link DNS-320 Remote Code Execution Vulnerability The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
CVE-2019-16057 Exploit Probability: 86.5%
April 15, 2022
D-Link Multiple Routers Remote Code Execution Vulnerability A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
CVE-2021-45382 Exploit Probability: 97.8%
April 4, 2022

Of the known exploited vulnerabilities above, 15 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 3 known exploited D Link vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest D Link Vulnerabilities

Based on the current exploit probability, these D Link vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2024-3273 100.0% D-Link Multiple NAS Devices Command Injection Vulnerability
2 CVE-2019-16920 100.0% D-Link Multiple Routers Command Injection Vulnerability
3 CVE-2020-25506 100.0% D-Link DNS-320 Command Injection Remote Code Execution Vulnerability
4 CVE-2024-3272 98.0% D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
5 CVE-2023-25280 97.9% D-Link DIR-820 Router OS Command Injection Vulnerability
6 CVE-2021-45382 97.8% D-Link Multiple Routers Remote Code Execution Vulnerability
7 CVE-2020-25078 97.5% D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
8 CVE-2015-2051 97.1% D-Link DIR-645 Router Remote Code Execution Vulnerability
9 CVE-2019-20500 96.7% D-Link DWL-2600AP Access Point Command Injection Vulnerability
10 CVE-2018-6530 96.7% D-Link Multiple Routers OS Command Injection Vulnerability

By the Year

In 2026 there have been 58 vulnerabilities in D Link with an average score of 7.7 out of ten. Last year, in 2025 D Link had 8 security vulnerabilities published. That is, 50 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.43.




Year Vulnerabilities Average Score
2026 58 7.73
2025 8 6.30
2024 1 0.00
2023 5 0.00
2022 2 9.80
2021 1 9.80
2020 1 0.00
2019 2 0.00
2018 6 7.70

It may take a day or so for new D Link vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent D Link Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-96891 Sep 24, 2026
D-Link DIR-825 3.00b32 rp-l2tp tunnel_set_params OOB Write via peer_hostname A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.
Dir 825
CVE-2026-94089 Sep 20, 2026
DIR-868L 2.01b05 Auth Handler Stack Buffer Overflow via strcpy A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Dir 868l
CVE-2026-94050 Sep 20, 2026
D-Link DIR-X1860Z ubus JSON-RPC Info Disclosure (pre-1.0.7) A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure. The attack must be carried out from within the local network. Upgrading to version 1.0.7.260821.161908 is able to address this issue. It is suggested to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
Dir X1860z
CVE-2026-94036 Sep 20, 2026
D-Link DIR-X1860 routerd/ubus passwd_set access control flaw <=1.0.2.220120.165402 A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.
Dir X1860
Dir X1860z
CVE-2026-93958 Sep 20, 2026
D-Link R95 1.00.16 OS Cmd Injection via /bin/ssi (NTPServer) A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
R95
CVE-2026-91003 Sep 15, 2026
Stack-based buffer overflow in D-Link DI8300 16.07 CGI svc (rzgl_asp) A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Di 8300
CVE-2026-91001 Sep 15, 2026
Stack Buffer Overflow in D-Link DI-8400 16.07 DDNS ddns_asp A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Di 8400
CVE-2026-90881 Sep 15, 2026
DIR-882 CGI Binary Info Disclosure via dllog.cgi A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Dir 882
CVE-2026-90880 Sep 15, 2026
D-Link DSL-3782 CGI Diagnostic Cmd Injection A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Dsl 3782
CVE-2026-90706 Sep 14, 2026
D-Link DWR-M921 1.1.52 OS Command Injection via formWsc TargetAPSsid A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Dwr M921
CVE-2026-90705 Sep 14, 2026
D-Link DWR-M921 1.1.52 FormsysCmd OS cmd injection via sysCmd A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Dwr M921
CVE-2026-90704 Sep 14, 2026
D-Link DWR-M921 1.1.52 Command Injection via devicename /boafrm/formDiskPartition A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Dwr M921
CVE-2026-90703 Sep 14, 2026
D-Link DWR-M921 1.1.52 OS Command Injection via formDiskCreateShare A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Dwr M921
CVE-2026-90702 Sep 14, 2026
Command Injection via /boafrm/formDiskFormat in D-Link DWR-M921 1.1.52 Remote Exploit A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Dwr M921
CVE-2026-90699 Sep 14, 2026
D-Link DWR-M920 1.1.7 Command Injection in formPinManageSetup A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Dwr M920
CVE-2026-90693 Sep 14, 2026
D-Link DIR-878 SetWan3Settings Buffer Overflow via Primary/Secondary manipulation A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the attack is possible.
Dir 878
CVE-2026-90692 Sep 14, 2026
Stack Buffer Overflow in D-Link DIR-878 Dynamic DNS IPv6 Settings A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overflow. The attack may be launched remotely.
Dir 878
CVE-2026-90680 Sep 14, 2026
Stack Overflow in D-Link DIR-823G 1.0.2B05 HNAP1 strcpy A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
Dir 823g
CVE-2026-86510 Sep 08, 2026
OOB Write in D-Link DIR-822A L2TP Parser via tunnel_set_params A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Dir 822a
CVE-2026-86509 Sep 08, 2026
Stack buffer overflow in D-Link DIR-895L udhcpcd sendOffer/sendACK A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.
Dir 895l
CVE-2026-86297 Sep 07, 2026
D-Link DIR-605 L2TP Off-by-One via peer_hostname A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Dir 605
CVE-2026-86296 Sep 07, 2026
DIR-822A udhcpcd Stack BOverflow via strcpy A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Dir 822a
CVE-2026-86295 Sep 07, 2026
CVE-2026-86295: D-Link DIR-895L Remote Command Injection via udhcpcd sendACK A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Dir 895l
CVE-2026-85224 Sep 03, 2026
D-Link DNS-320 v2.06B01 File Sharing CGI OS Command Injection via fileurl A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Dns 320 Sharecenter
CVE-2026-85223 Sep 03, 2026
D-Link DNS-340L 1.01B04 Remote OS Command Injection via CGI Handler A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Dns 340l
CVE-2026-85222 Sep 03, 2026
D-Link DNS340L 1.01B04 AddOn Center CGI OS Command Injection Remote A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Dns 340l
CVE-2026-82692 Aug 31, 2026
D-Link DNS-340L/DNS-345 OS Command Injection via iscsi_mgr.cgi A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Dns 340l
Dns 345
CVE-2026-82691 Aug 31, 2026
OS Command Injection via usb_device CGI on D-Link DNS-32xL Series A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Dns 320l
Dns 327l
Dns 340l
And others...
CVE-2026-82690 Aug 31, 2026
D-Link DNS-327L/DNS-340L: os Command Injection via CGI Argument f_dev (remote) A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Dns 327l
Dns 340l
CVE-2026-82689 Aug 31, 2026
D-Link DNS Router OS Command Injection via ISO Image Handler (CVE-2026-82689) A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
Dns 320l
Dns 327l
Dns 340l
And others...
CVE-2026-82688 Aug 31, 2026
D-Link DNS-340L/345 OS command injection via Virtual Volume Handler before 1.05b04 A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Dns 340l
Dns 345
CVE-2026-82680 Aug 31, 2026
D-Link DSM-G600 1.01 OOB Write via Multipart Handler in /load_file.cgi A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a manipulation can lead to out-of-bounds write. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Dsm G600
CVE-2026-82595 Aug 30, 2026
DIR-825M 1.1.8 Remote Command Injection via sysCmd (sub_456CF4) A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Dir 825m
CVE-2026-82593 Aug 30, 2026
Remote Stack Buffer Overflow in D-Link DIR-825M 1.1.8 LTE Module Firmware Upgrade A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Dir 825m
CVE-2026-82592 Aug 30, 2026
D-Link DIR-825M 1.1.8 stack-buffer overflow in Disk Format Handler A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
Dir 825m
CVE-2026-19893 Aug 15, 2026
DIR-842 2.01.B04 vsftpd: Incorrect default perms via /etc/vsftpd.conf (remote) A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.
Dir 842
CVE-2026-16448 Jul 21, 2026
D-Link DNS- series cmdinject in remote_backup.cgi A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Dns 120
Dnr 202l
Dns 315l
And others...
CVE-2026-16447 Jul 21, 2026
Unrestricted Upload via Filedata[] in D-Link DNS-320 1.0.2 (multi_uploadify.php) A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Dns 320
CVE-2026-16332 Jul 21, 2026
Unrestricted File Upload in D-Link DNS-320 1.0.2 via multi_uploadify.php A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Dns 320
CVE-2026-16331 Jul 21, 2026
Unrestricted Upload in D-Link DNS-320 1.0.2 /save_ajax.php A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Dns 320
CVE-2026-16330 Jul 21, 2026
D-Link DNS320 1.0.2: Unrestricted File Upload via uploadify.php A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Dns 320
CVE-2026-16329 Jul 21, 2026
D-Link DNS-320 1.0.2 Unrestricted File Upload via uploadify.php A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
Dns 320
CVE-2026-16327 Jul 20, 2026
D-Link DNS-320 1.0.2 Remote Unrestricted File Upload via /web/web_file/upload.php A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Dns 320
CVE-2026-15270 Jul 09, 2026
Least Privilege Violation in D-Link DIR-823G (1.0.2B05) via /etc/boa/boa.conf A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.
Dir 823g
CVE-2026-13545 Jun 29, 2026
Command Injection in D-Link DCS-935L 1.10.01 POST Handler (before v1.10.02) A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi of the component POST Parameter Handler. Such manipulation of the argument UID leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Dcs 935l
CVE-2026-12174 Jun 13, 2026
D-Link DCS-935L 1.10.01 fmtstr via snprintf in HTTP Handler A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Dcs 935l
CVE-2026-11555 Jun 08, 2026
D-Link DGS-1100-08PD 1.00.006 WebInterface /etc/boa.conf LVP A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Dgs 1100 08pd
CVE-2026-11497 Jun 08, 2026
Least Privilege Violation via Boa Webserver in D-Link DCS-5615 v1.01.00 A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Dcs 5615
CVE-2026-11492 Jun 08, 2026
Least Privilege Violation in vsftpd of D-Link DIR-823G 1.0.2B05 A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Dir 823g
CVE-2026-11341 Jun 05, 2026
Command Injection in D-Link DWR-M920 (<=1.1.50) via IMEI_setup A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.
Dwr M920
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.