D-Link Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for D-Link products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
50
In CISA KEV
27
Beyond CISA KEV
23
Sensor Observed
0
Virtual Patch Available
0
D-Link KEVs Added by Year
50 D-Link KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-1125
D-Link DIR-823X set_wifidog_settings sub_412E7C command injection |
DIR-823X | High | Not in CISA | 02 Jul 2026 |
|
CVE-2025-34048
D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read |
DSL-2730U, DSL-2750U, DSL-2750E | High | Not in CISA | 24 May 2026 |
|
CVE-2021-46381
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. |
DAP-1620 | High | Not in CISA | 31 Mar 2026 |
|
CVE-2023-4542
D-Link DAR-8000-10 sys1.php os command injection |
DAR-8000-10 | High | Not in CISA | 19 Mar 2026 |
|
CVE-2021-3708
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local... |
DSL-2750U | High | Not in CISA | 16 Jan 2026 |
|
CVE-2023-5074
Authentication Bypass in D-Link D-View 8 |
D-View 8 | High | Not in CISA | 17 Dec 2025 |
|
CVE-2019-13372
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary... |
Central WiFi Manager CWM(100) | High | Not in CISA | 28 Sep 2025 |
|
CVE-2020-24581
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not... |
DSL-2888A | High | Not in CISA | 01 Oct 2025 |
|
CVE-2019-13101
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can... |
DIR-600M | High | Not in CISA | 16 Sep 2025 |
|
CVE-2023-5148
D-Link DAR-7000/DAR-8000 uploadfile.php unrestricted upload |
DAR-7000, DAR-8000 | High | Not in CISA | 26 Jun 2025 |
|
CVE-2025-29635
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote... |
DIR-823X | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-0625
D-Link DSL/DIR/DNS Authentication Bypass via DNS Configuration Endpoint |
DSL-2640B, DSL-2740R, DSL-2780B, DSL-526B, DSL-2640T, DSL-500, DSL-500G, DSL-502G, DIR-905L, DIR-600, DIR-608, DIR-610, DIR-611, DIR-615, DNS-320, DNS-325, DNS-345 | High | Not in CISA | 01 Jun 2026 |
|
CVE-2022-37055
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main, |
Go-RT-AC750 | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2022-40799
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the... |
DNR-322L | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-25079
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated... |
DCS-2530L, DCS-2670L | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2020-25078
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint... |
DCS-2530L, DCS-2670L | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-0769
D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal |
DIR-859 | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-25120
D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test |
DNS-343 ShareCenter | High | Not in CISA | 29 Oct 2025 |
|
CVE-2025-5571
D-Link DCS-932L setSystemAdmin os command injection |
DCS-932L | High | Not in CISA | 04 Jun 2025 |
|
CVE-2013-6026
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and... |
["DIR-100", "DIR-120", "DI-624S", "DI-524UP", "DI-604S", "DI-604UP", "DI-604+", "TM-G5240", "BRL-04R", "BRL-04UR", "BRL-04CW"] | High | Not in CISA | 19 Oct 2013 |
|
CVE-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection |
DNS-320, DNS-320LW, DNS-325, DNS-340L | High | Not in CISA | 24 Apr 2025 |
|
CVE-2019-17506
There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the... |
DIR-868L, DIR-817LW | High | Not in CISA | 27 Apr 2025 |
|
CVE-2020-25506
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code... |
DNS-320 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-29557
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to... |
DIR-825 R1 | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2015-2051
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a... |
DIR-645 Wired/Wireless Router | Confirmed | In CISA | 10 Feb 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 20
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 8
- CWE-306 — Missing Authentication for Critical Function 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
- CWE-798 — Use of Hard-coded Credentials 2
- CWE-287 — Improper Authentication 2
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
- CWE-312 — Cleartext Storage of Sensitive Information 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology