Dir 600l
Vendor:
First CVE: May 1, 2015 · Active for 11 years
38
Total CVEs
More Total CVEs than 97% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Dir 600l over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2015
11 years ago
Most Recent CVE
May 4, 2026
82 days ago
CVE Severity & Scoring
Dir 600l38 CVEs
63%
37%
All CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network36 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (5.3%)
Attack Complexity
Low37 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None38 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None38 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8361CRITICAL The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | May 1, 2015 | 9.8 | 98 | YES | YES |
CVE-2026-42375HIGH D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetwo | May 4, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-42374HIGH D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetwo | May 4, 2026 | 8.8 | 35 | NO | NO |
CVE-2025-60553CRITICAL D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard52. | Oct 24, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-60548CRITICAL D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettings. | Oct 24, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-4350CRITICAL A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the function wake_on_lan. The manipulation of the argument host leads | May 6, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-60554CRITICAL D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEnableWizard. | Oct 24, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4347CRITICAL A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been declared as critical. Affected by this vulnerability is the function formWlSiteSurvey. The manipulation of t | May 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-4342CRITICAL A vulnerability, which was classified as critical, has been found in D-Link DIR-600L up to 2.07B01. Affected by this issue is the function formEasySetupWizard3. The manipulation of | May 6, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-4348CRITICAL A vulnerability was found in D-Link DIR-600L up to 2.07B01. It has been rated as critical. Affected by this issue is the function formSetWanL2TP. The manipulation of the argument h | May 6, 2025 | 9.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
1 CVE
2.6% of CVEs· 96th percentile
Metasploit
1 CVE
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Dir 600l
Top CWEs
Versions
No cataloged versions.