D-Link's vulnerability footprint spans a broadly represented portfolio of consumer and small-business networking devices, particularly its DIR-series routers and firmware, positioning these internet-facing appliances as a substantial attack surface in the landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, consistent with the appeal of accessible embedded devices for remote compromise and lateral pivoting. The exposure recurs through memory-safety and command-injection weakness classes—including stack-based buffer overflows, OS command injection, out-of-bounds writes, and command-injection variants—that are endemic to embedded firmware implementations and parser logic. Defenders should inventory affected D-Link devices across their environment, prioritize patching for internet-reachable instances, and consider network segmentation for older or unsupported models; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dlink over time
Signals from CVEs in this vendor scope (1812 CVEs).
1,812 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3273CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unkno | Apr 4, 2024 | 9.8 | 98 | YES | YES |
CVE-2020-25506CRITICAL D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution. | Feb 2, 2021 | 9.8 | 98 | YES | YES |
CVE-2019-16920CRITICAL Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a | Sep 27, 2019 | 9.8 | 98 | YES | YES |
CVE-2014-8361CRITICAL The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | May 1, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-2051HIGH The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP | Feb 23, 2015 | 8.8 | 98 | YES | YES |
CVE-2024-3272CRITICAL ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue | Apr 4, 2024 | 9.8 | 97 | YES | YES |
CVE-2023-25280CRITICAL OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. | Mar 16, 2023 | 9.8 | 97 | YES | YES |
CVE-2021-45382CRITICAL A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in nc | Feb 17, 2022 | 9.8 | 97 | YES | YES |
CVE-2020-25078HIGH An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticated /config/getuser endpoint allows for remote administrator p | Sep 2, 2020 | 7.5 | 97 | YES | YES |
CVE-2019-17621CRITICAL The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending | Dec 30, 2019 | 9.8 | 97 | YES | YES |
Signals from CVEs in this vendor scope (1812 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dlink.
Media articles that mention a CVE ID that affects a product developed by Dlink — matched by CVE ID, not by vendor name.