D-Link Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for D-Link products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

50

In CISA KEV

27

Beyond CISA KEV

23

Sensor Observed

0

Virtual Patch Available

0

D-Link KEVs Added by Year

Loading...

50 D-Link KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2026-1125

D-Link DIR-823X set_wifidog_settings sub_412E7C command injection

High Not in CISA 02 Jul 2026
CVE-2025-34048

D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read

High Not in CISA 24 May 2026
CVE-2021-46381

Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

High Not in CISA 31 Mar 2026
CVE-2023-4542

D-Link DAR-8000-10 sys1.php os command injection

High Not in CISA 19 Mar 2026
CVE-2021-3708

D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local...

High Not in CISA 16 Jan 2026
CVE-2023-5074

Authentication Bypass in D-Link D-View 8

High Not in CISA 17 Dec 2025
CVE-2019-13372

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary...

High Not in CISA 28 Sep 2025
CVE-2020-24581

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not...

High Not in CISA 01 Oct 2025
CVE-2019-13101

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can...

High Not in CISA 16 Sep 2025
CVE-2023-5148

D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload

High Not in CISA 26 Jun 2025
CVE-2025-29635

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote...

Confirmed In CISA 01 Jun 2026
CVE-2026-0625

D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint

High Not in CISA 01 Jun 2026
CVE-2022-37055

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

Confirmed In CISA 01 Jun 2026
CVE-2022-40799

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the...

Confirmed In CISA 01 Jun 2026
CVE-2020-25079

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated...

Confirmed In CISA 01 Jun 2026
CVE-2020-25078

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint...

Confirmed In CISA 01 Jun 2026
CVE-2024-0769

D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal

Confirmed In CISA 01 Jun 2026
CVE-2018-25120

D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test

High Not in CISA 29 Oct 2025
CVE-2025-5571

D-Link DCS-932L setSystemAdmin os command injection

High Not in CISA 04 Jun 2025
CVE-2013-6026

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and...

High Not in CISA 19 Oct 2013
CVE-2024-10914

D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection

High Not in CISA 24 Apr 2025
CVE-2019-17506

There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the...

High Not in CISA 27 Apr 2025
CVE-2020-25506

D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code...

Confirmed In CISA 03 Nov 2021
CVE-2020-29557

An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to...

Confirmed In CISA 03 Nov 2021
CVE-2015-2051

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a...

Confirmed In CISA 10 Feb 2022

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 20
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 8
  • CWE-306 — Missing Authentication for Critical Function 3
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
  • CWE-798 — Use of Hard-coded Credentials 2
  • CWE-287 — Improper Authentication 2
  • CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
  • CWE-312 — Cleartext Storage of Sensitive Information 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology