D-Link Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for D-Link products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
50
In CISA KEV
27
Beyond CISA KEV
23
Sensor Observed
0
Virtual Patch Available
0
D-Link KEVs Added by Year
50 D-Link KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2013-5223
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web... |
DSL-2760U Gateway | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2015-1187
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. |
multiple devices | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-11021
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter. |
DCS-930L | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-16920
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the... |
DIR-655C, DIR-866L, DIR-652, DHP-1565, DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, DIR-825 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2020-9377
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are... |
DIR-610 | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2021-45382
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L... |
DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, DIR-836L routers | Confirmed | In CISA | 04 Apr 2022 |
|
CVE-2019-16057
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. |
DNS-320 | Confirmed | In CISA | 15 Apr 2022 |
|
CVE-2011-4723
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified... |
DIR-300 | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2018-6530
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous... |
DIR-880L, DIR-868L, DIR-865L, DIR-860L | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2022-26258
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp. |
DIR-820L | Confirmed | In CISA | 08 Sep 2022 |
|
CVE-2019-20500
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the... |
DWL-2600AP | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2019-17621
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute... |
DIR-859 Wi-Fi router | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2016-20017
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in... |
DSL-2750B | Confirmed | In CISA | 08 Jan 2024 |
|
CVE-2024-3272
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials |
DNS-320L, DNS-325, DNS-327L, DNS-340L | Confirmed | In CISA | 11 Apr 2024 |
|
CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection |
DNS-320L, DNS-325, DNS-327L, DNS-340L | Confirmed | In CISA | 11 Apr 2024 |
|
CVE-2014-100005
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers... |
DIR-600 router | Confirmed | In CISA | 16 May 2024 |
|
CVE-2021-40655
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a... |
DIR-605 B2 Firmware | Confirmed | In CISA | 16 May 2024 |
|
CVE-2023-25280
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the... |
DIR820LA1_FW105B03 | Confirmed | In CISA | 30 Sep 2024 |
|
CVE-2021-46442
In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such... |
DIR-825 G1 | High | Not in CISA | 27 Apr 2022 |
|
CVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. |
DIR850 | High | Not in CISA | 04 Mar 2022 |
|
CVE-2021-39509
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of... |
DIR-816 | High | Not in CISA | 24 Aug 2021 |
|
CVE-2020-10215
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name... |
DIR-825 Rev.B 2.10 | High | Not in CISA | 07 Mar 2020 |
|
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635... |
DCS-3411/3430, DCS-5605/5635, DCS-1100L/1130L, DCS-1100/1130, DCS-2102/2121, DCS-3410, DCS-5230, DCS-6410, DCS-7410, DCS-7510, WCS-1100 | High | Not in CISA | 28 Jan 2020 |
|
CVE-2018-15517
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually... |
Central WiFiManager CWM-100 | High | Not in CISA | 31 Jan 2019 |
|
CVE-2018-10823
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and... |
DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, DWR-111 | High | Not in CISA | 17 Oct 2018 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 20
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 8
- CWE-306 — Missing Authentication for Critical Function 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 3
- CWE-798 — Use of Hard-coded Credentials 2
- CWE-287 — Improper Authentication 2
- CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') 2
- CWE-312 — Cleartext Storage of Sensitive Information 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology