D-Link

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any D-Link product.

RSS Feeds for D-Link security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in D-Link products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by D-Link Sorted by Most Security Vulnerabilities since 2018

 

D-Link Dap 2622 Firmware54 vulnerabilities

 

D-Link Dir 619l Firmware44 vulnerabilities

 

D-Link Dir 605l Firmware41 vulnerabilities

 

D-Link Dap 1325 Firmware37 vulnerabilities

 

D-Link Dir 816 Firmware33 vulnerabilities

 

D-Link Dir 823g Firmware29 vulnerabilities

 

D-Link Dir X3260 Firmware23 vulnerabilities

 

D-Link Dwr M96022 vulnerabilities

 

D-Link G416 Firmware21 vulnerabilities

 

D-Link D View 819 vulnerabilities

 

D-Link Di 8100 Firmware17 vulnerabilities

 

D-Link Dir 3040 Firmware17 vulnerabilities

 

D-Link Dar 7000 Firmware14 vulnerabilities

 

D-Link Dwr M92014 vulnerabilities

 

D-Link Di 7003g Firmware12 vulnerabilities

 

D-Link Go Rt Ac750 Firmware11 vulnerabilities

 

D-Link Dir 878 Firmware10 vulnerabilities

 

D-Link Dir 882 A1 Firmware10 vulnerabilities

 

D-Link Dir 2150 Firmware10 vulnerabilities

 

D-Link Dir 600l Firmware9 vulnerabilities

 

D-Link Dsl 3782 Firmware9 vulnerabilities

 

D-Link Dir 823x Firmware9 vulnerabilities

 

D-Link Dir 2640 Firmware8 vulnerabilities

 

D-Link Dir 822k8 vulnerabilities

 

D-Link Dcs 932l Firmware7 vulnerabilities

 

D-Link Di 8003 Firmware7 vulnerabilities

 

D-Link Dsl6740c Firmware7 vulnerabilities

 

D-Link Dir 853 Firmware7 vulnerabilities

 

D-Link Dcs 8300lhv2 Firmware6 vulnerabilities

 

D-Link Dwr M9216 vulnerabilities

 

D-Link Dir 513 Firmware6 vulnerabilities

 

D-Link Dir 820l Firmware6 vulnerabilities

 

D-Link Dir 822 Firmware6 vulnerabilities

 

D-Link Dir 825 Firmware6 vulnerabilities

 

D-Link Dir 845l Firmware6 vulnerabilities

 

D-Link Dir 846 Firmware6 vulnerabilities

 

D-Link Dwl 6610ap Firmware5 vulnerabilities

 

D-Link Dir 882 Firmware5 vulnerabilities

 

D-Link Dir 6005 vulnerabilities

 

D-Link Dir 816 A2 Firmware5 vulnerabilities

 

D-Link Dir 825m5 vulnerabilities

 

D-Link Nuclias Connect4 vulnerabilities

 

D-Link Dap 1520 Firmware4 vulnerabilities

 

D-Link Dap 1620 Firmware4 vulnerabilities

 

D-Link Dns 320 Firmware4 vulnerabilities

 

D-Link Dir 868l Firmware4 vulnerabilities

 

D-Link Di 8100g Firmware4 vulnerabilities

 

D-Link Di 8200 Firmware4 vulnerabilities

 

D-Link Dir 645 Firmware4 vulnerabilities

 

D-Link Dir 846w Firmware4 vulnerabilities

 

D-Link Dap 2695 Firmware3 vulnerabilities

 

D-Link Dar 8000 Firmware3 vulnerabilities

 

D-Link Dir X4860 Firmware3 vulnerabilities

 

D-Link Dir 890l Firmware3 vulnerabilities

 

D-Link Di 7300g Firmware3 vulnerabilities

 

D-Link Dir 1003 vulnerabilities

 

D-Link Dir 600 Firmware3 vulnerabilities

 

D-Link Dir 632 Firmware3 vulnerabilities

 

D-Link Dir 6453 vulnerabilities

 

D-Link Dir 860l Firmware3 vulnerabilities

 

D-Link Dir 815 Firmware3 vulnerabilities

 

D-Link Dir 816l3 vulnerabilities

 

D-Link Dwr 2000m Firmware3 vulnerabilities

 

D-Link Dap 1320 Firmware2 vulnerabilities

 

D-Link Dap 1562 Firmware2 vulnerabilities

 

D-Link Dsl 225 Firmware2 vulnerabilities

 

D-Link Dap 26952 vulnerabilities

 

D-Link Dsp W215 Firmware2 vulnerabilities

 

D-Link Dsl 2740r Firmware2 vulnerabilities

 

D-Link Dcs 960l Firmware2 vulnerabilities

 

D-Link Dhp W310av Firmware2 vulnerabilities

 

D-Link Dsl 224 Firmware2 vulnerabilities

 

D-Link Di 8004w Firmware2 vulnerabilities

 

D-Link Di 8300 Firmware2 vulnerabilities

 

D-Link Di 8400 Firmware2 vulnerabilities

 

D-Link Dir 300 Firmware2 vulnerabilities

 

D-Link Dir 867 Firmware2 vulnerabilities

 

D-Link Dns 325 Firmware2 vulnerabilities

 

D-Link Dir 610 Firmware2 vulnerabilities

 

D-Link Dns 320l Firmware2 vulnerabilities

 

D-Link Dir878 Firmware2 vulnerabilities

 

D-Link Dsl 2750u Firmware2 vulnerabilities

 

D-Link Dns 340l Firmware2 vulnerabilities

 

D-Link Dwl 2600ap Firmware2 vulnerabilities

 

D-Link Dsl 6740c Firmware2 vulnerabilities

 

D-Link Dns 327l Firmware2 vulnerabilities

 

D-Link Dir 859 Firmware2 vulnerabilities

 

D-Link Dir 832x Firmware2 vulnerabilities

 

D-Link Dir 842v2 Firmware2 vulnerabilities

 
 

D-Link Dcs 7517 Firmware1 vulnerability

 

D-Link Dcs 930l Firmware1 vulnerability

 

D-Link Dir 1101 vulnerability

 

D-Link Dir 1950 Firmware1 vulnerability

 

D-Link Dir 1960 Firmware1 vulnerability

By the Year

In 2026 there have been 123 vulnerabilities in D-Link with an average score of 7.4 out of ten. Last year, in 2025 D-Link had 240 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in D-Link in 2026 could surpass last years number. Last year, the average CVE base score was greater by 0.78




Year Vulnerabilities Average Score
2026 123 7.35
2025 240 8.14
2024 347 8.49
2023 85 9.01
2022 39 9.05
2021 10 8.60
2020 11 8.00
2019 7 9.57
2018 5 7.70

It may take a day or so for new D-Link vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent D-Link Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-7289 Apr 28, 2026
D-Link DIR-825M 1.1.12 buffer overflow in sub_414BA8 via submit-url A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Dir 825m
CVE-2026-7288 Apr 28, 2026
D-Link DIR-825M 1.1.12 VPN Config Buffer Overflow (sub_4151FC) A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Dir 825m
CVE-2026-7248 Apr 28, 2026
D-Link DI-8100 16.07.26A1 CGI Buffer Overflow: tgfile_htm fn A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
CVE-2026-7247 Apr 28, 2026
D-Link DI-8100 16.07.26A1 File Extension Handler Buffer Overflow A vulnerability has been found in D-Link DI-8100 16.07.26A1. Affected by this issue is the function file_exten_asp of the file file_exten.asp of the component File Extension Handler. The manipulation of the argument Name leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVE-2026-7069 Apr 27, 2026
D-Link DIR-825 miniupnpd buffer overflow via AddPortMapping (3.00b32) A security flaw has been discovered in D-Link DIR-825 up to 3.00b32. This impacts the function AddPortMapping of the file upnpsoap.c of the component miniupnpd. Performing a manipulation of the argument NewPortMappingDescription results in buffer overflow. The attack needs to be approached within the local network. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-7068 Apr 26, 2026
D-Link DIR-825 3.00b32 nmbd Buffer Overflow (Local Net) A vulnerability was identified in D-Link DIR-825 3.00b32. This affects the function NMBD_process of the file sserver.c of the component nmbd. Such manipulation leads to buffer overflow. The attack can only be initiated within the local network. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-7067 Apr 26, 2026
Command Injection in D-Link DIR-822 udhcpd DHCP Service A vulnerability was determined in D-Link DIR-822 A_101. The impacted element is the function system of the file /udhcpcd/dhcpd.c of the component udhcpd DHCP Service. This manipulation of the argument Hostname causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-7027 Apr 26, 2026
D-Link DSL-2740R EU_01.15 Wireless Setup XSS via Network Name A vulnerability was identified in D-Link DSL-2740R EU_01.15. Impacted is an unknown function of the component Wireless Setup Section. Such manipulation of the argument Wireless Network Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used.
CVE-2026-7026 Apr 26, 2026
D-Link DGS-3420 1.50.018 XSS via System Name on Sys Info Settings Page A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the argument System Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVE-2026-6947 Apr 24, 2026
D-Link DWM-222W Brute-Force Protection Bypass in USB WiFi Adapter DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform brute-force attacks to gain control over the device.
CVE-2026-6014 Apr 10, 2026
D-Link DIR-513 1.10 buffer overflow in formAdvanceSetup (POST) A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-6013 Apr 10, 2026
D-Link DIR-513 1.10 Remote Buffer Overflow via formSetRoute A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-6012 Apr 10, 2026
D-Link DIR-513 1.10 Buffer Overflow via formSetPassword POST Handler A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5984 Apr 09, 2026
D-Link DIR-605L 2.13B01 Buffer Overflow in formSetLog (CVE-2026-5984) A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formSetLog of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5983 Apr 09, 2026
D-Link DIR-605L 2.13B01 Buffer Overflow via formSetDDNS curTime A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /goform/formSetDDNS of the component POST Request Handler. Executing a manipulation of the argument curTime can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5982 Apr 09, 2026
D-Link DIR-605L 2.13B01 Buffer Overflow in formAdvNetwork (curTime) A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file /goform/formAdvNetwork of the component POST Request Handler. Performing a manipulation of the argument curTime results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5981 Apr 09, 2026
Buffer Overflow in D-Link DIR-605L 2.13B01 formAdvFirewall (curTime) A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5980 Apr 09, 2026
DIR-605L 2.13B01 POST RF Buffer Overflow in formSetMACFilter A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5979 Apr 09, 2026
D-Link DIR-605L 2.13B01 Remote Buffer Overflow in formVirtualServ A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5844 Apr 09, 2026
D-Link DIR-882 1.01B02 HNAP1 OS Command Injection via sprintf A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the component HNAP1 SetNetworkSettings Handler. The manipulation of the argument IPAddress results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-5815 Apr 08, 2026
Stack Buffer Overflow in D-Link DIR-645 1.01-1.03 via hedwigcgi_main A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Dir 645
CVE-2026-5312 Apr 01, 2026
Improper Access Control in D-Link DNS via /cgi-bin/dsk_mgr.cgi A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function FMT_restart/Status_HDInfo/SMART_List/ScanDisk_info/ScanDisk/volume_status/Get_Volume_Mapping/FMT_check_disk_remount_state/FMT_rebuildinfo/FMT_result_list/FMT_result_list_phy/FMT_get_dminfo/FMT_manually_rebuild_info/Get_current_raidtype of the file /cgi-bin/dsk_mgr.cgi. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-5311 Apr 01, 2026
D-Link WebDAV cmd Argument Manipulation Enables ACL Bypass A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function Webdav_Access_List of the file /cgi-bin/file_center.cgi. Performing a manipulation of the argument cmd results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-5215 Mar 31, 2026
D-Link DNS Series Improper Access Control in cgi_get_ipv6 A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_get_ipv6 of the file /cgi-bin/network_mgr.cgi. Such manipulation leads to improper access controls. The exploit is publicly available and might be used.
CVE-2026-5214 Mar 31, 2026
Remote Stack Buffer Overflow in D-Link DNS Router Account Manager CGI A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_addgroup_get_group_quota_minsize of the file /cgi-bin/account_mgr.cgi. The manipulation of the argument Name results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
CVE-2026-5213 Mar 31, 2026
Stack Buffer Overflow in D-Link DNS Router cgi_adduser_to_session A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_adduser_to_session of the file /cgi-bin/account_mgr.cgi. This manipulation of the argument read_list causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-5212 Mar 31, 2026
Stack Buffer Overflow in D-Link DNS Router Webdav_Upload_File A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function Webdav_Upload_File of the file /cgi-bin/webdav_mgr.cgi. The manipulation of the argument f_file leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-5211 Mar 31, 2026
Stack-Based Buffer Overflow in D-Link DNS Router UPnP AV Server A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnP_AV_Server_Path_Del of the file /cgi-bin/app_mgr.cgi. Executing a manipulation of the argument f_dir can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
CVE-2026-5024 Mar 29, 2026
D-Link DIR-513 1.10 SSB in formSetEmail via curTime (remote) A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formSetEmail. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-4627 Mar 24, 2026
D-Link DIR-825/825R OS Command Injection in NTP Service (v4.5.1) A vulnerability was found in D-Link DIR-825 and DIR-825R 1.0.5/4.5.1. Affected is the function handler_update_system_time of the file libdeuteron_modules.so of the component NTP Service. The manipulation results in os command injection. The attack may be launched remotely. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-4555 Mar 22, 2026
D-Link DIR-513 1.10 Stack Buffer Overflow in boa's formEasySetTimezone (curTime) A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-4529 Mar 21, 2026
D-Link DHP-1320 1.00WWB04 SOAP Handler Stack Buffer Overflow Remote Exploit A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-4499 Mar 20, 2026
D-Link DIR-820LW 2.03 SSDP cmd injection via ssdpcgi_main A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-4486 Mar 20, 2026
Stack overflow in D-Link DIR-513 1.10 Web Service (formEasySetPassword) A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-4465 Mar 20, 2026
D-Link DIR-513 1.10 OS Command Injection via /goform/formSysCmd A flaw has been found in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formSysCmd. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-4214 Mar 16, 2026
Stack Buffer Overflow in D-Link DNS UPnP AV Server Path Setting A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnP_AV_Server_Path_Setting of the file /cgi-bin/app_mgr.cgi. Executing a manipulation can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.
CVE-2026-4213 Mar 16, 2026
Stack Buffer Overflow in D-Link DNS Router cgi_myfavorite CGI A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function cgi_myfavorite_del_user/cgi_myfavorite_verify of the file /cgi-bin/gui_mgr.cgi. Performing a manipulation results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
CVE-2026-4212 Mar 16, 2026
D-Link DNS-120 Series Stack-Buffer Overflow via Downloads_Schedule_Info A security vulnerability has been detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects the function Downloads_Schedule_Info of the file /cgi-bin/download_mgr.cgi. Such manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-4211 Mar 16, 2026
D-Link DNS Series Buffer Overflow via Local_Backup_Info A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this issue is the function Local_Backup_Info of the file /cgi-bin/local_backup_mgr.cgi. This manipulation of the argument f_idx causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-4210 Mar 16, 2026
CGI Command Injection in D-Link DNS Routers (CVE-2026-4210) A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function cgi_tm_set_share of the file /cgi-bin/time_machine.cgi. The manipulation of the argument Name results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
CVE-2026-4209 Mar 16, 2026
D-Link DNS Series Command Injection via /cgi-bin/account_mgr CGI A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function cgi_create_import_users/cgi_user_batch_create/cgi_user_set_quota/cgi_user_del/cgi_user_modify/cgi_group_set_quota/cgi_group_modify/cgi_group_add/cgi_user_add/cgi_get_modify_group_info/cgi_chg_admin_pw of the file /cgi-bin/account_mgr.cgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
CVE-2026-4207 Mar 16, 2026
Command Injection in D-Link DNS-120 Router cgi via System Manager CGI A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgi_device/cgi_sms_test/cgi_firmware_upload/cgi_ntp_time of the file /cgi-bin/system_mgr.cgi. Executing a manipulation can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
CVE-2026-4206 Mar 16, 2026
D-Link DNS Router Command Injection via /cgi-bin/dsk_mgr.cgi A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects the function FMT_rebuild_diskmgr/FMT_create_diskmgr/ScanDisk_run_e2fsck of the file /cgi-bin/dsk_mgr.cgi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVE-2026-4205 Mar 16, 2026
D-Link DNS Series Command Injection via /cgi-bin/App_Mgr.cgi (FTP_BlockIP) A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_refresh_db/FTP_Server_BlockIP_Add/FTP_Server_BlockIP_Del of the file /cgi-bin/app_mgr.cgi. Such manipulation leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-4204 Mar 16, 2026
D-Link DNS Series Cmd Injection via CGI f_user A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_myfavorite_add/cgi_myfavorite_set/cgi_myfavorite_del/cgi_myfavorite_set_sort_info/cgi_myfavorite_remove_apkg/cgi_myfavorite_compare_apkg/cgi_mycloud_auto_downlaod of the file /cgi-bin/gui_mgr.cgi. This manipulation of the argument f_user causes command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVE-2026-4203 Mar 16, 2026
Command Injection in D-Link Router CGI (DNS Series) A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_portforwarding_add/cgi_portforwarding_del/cgi_portforwarding_modify/cgi_portforwarding_add_scan/cgi_dhcpd_lease/cgi_ddns/cgi_ip/cgi_dhcpd of the file /cgi-bin/network_mgr.cgi. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
CVE-2026-4197 Mar 15, 2026
D-Link DNS Router Command Injection via download_mgr.cgi A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function RSS_Get_Update_Status/RSS_Update/RSS_Channel_AutoDownlaod/RSS_Add/RSS_Channel_Item_Downlaod/RSS_History_Item_List/RSS_Item_List of the file /cgi-bin/download_mgr.cgi. The manipulation results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.
CVE-2026-4196 Mar 15, 2026
D-Link DNS Series: Remote Command Injection via /cgi-bin/remote_backup.cgi A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgi_recovery/cgi_backup_now/cgi_set_schedule/cgi_set_rsync_server of the file /cgi-bin/remote_backup.cgi. The manipulation leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-4195 Mar 15, 2026
Command Injection in D-Link DNS series via /cgi-bin/wizard_mgr.cgi A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects an unknown function of the file /cgi-bin/wizard_mgr.cgi. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used.
CVE-2026-4194 Mar 15, 2026
D-Link DNS Series Remote Access Control Bypass via cgi_set_wto A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_set_wto of the file /cgi-bin/system_mgr.cgi. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.