D Link
D-Link's vulnerability footprint centers on a moderate portfolio of consumer and small-business networking devices, including routers and residential gateways such as the DIR and DSL lines, which are often deployed with extended operational lifespans. The exposure spans input-validation and authentication weaknesses typical of embedded network appliances, reflecting the constraints of firmware-based implementations. Defenders should prioritize inventory of affected models and assess management-interface exposure, particularly for end-of-life units; current severity, exploitation activity, and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by D Link over time
Products(128 total)
Top CVEs
Signals from CVEs in this vendor scope (1812 CVEs).
1,812 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3273CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unkno | Apr 4, 2024 | 9.8 | 98 | YES | YES |
CVE-2020-25506CRITICAL D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution. | Feb 2, 2021 | 9.8 | 98 | YES | YES |
CVE-2019-16920CRITICAL Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a | Sep 27, 2019 | 9.8 | 98 | YES | YES |
CVE-2014-8361CRITICAL The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | May 1, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-2051HIGH The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP | Feb 23, 2015 | 8.8 | 98 | YES | YES |
CVE-2024-3272CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue | Apr 4, 2024 | 9.8 | 97 | YES | YES |
CVE-2023-25280CRITICAL OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | Mar 16, 2023 | 9.8 | 97 | YES | YES |
CVE-2021-45382CRITICAL A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in nc | Feb 17, 2022 | 9.8 | 97 | YES | YES |
CVE-2020-25078HIGH An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator p | Sep 2, 2020 | 7.5 | 97 | YES | YES |
CVE-2019-17621CRITICAL The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending | Dec 30, 2019 | 9.8 | 97 | YES | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (1812 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by D Link.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by D Link — matched by CVE ID, not by vendor name.