Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

D-Link — Vulnerabilities & Security Advisories 825

Browse all 825 CVE security advisories affecting D-Link. AI-powered Chinese analysis, POCs, and references for each vulnerability.

D-Link manufactures networking hardware, primarily consumer-grade routers and wireless access points, serving as a critical infrastructure component for home and small business internet connectivity. The company’s product line has historically been plagued by significant security deficiencies, resulting in 760 recorded Common Vulnerabilities and Exposures. These flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from hardcoded credentials or unpatched firmware updates. A notable incident occurred in 2017 when a critical vulnerability allowed attackers to gain administrative control over millions of devices, facilitating large-scale botnet recruitment. The persistent lack of timely security patches and weak default configurations have established a pattern of neglect, leaving users exposed to persistent threats. This track record highlights systemic issues in the development and maintenance lifecycle of D-Link’s network equipment, necessitating rigorous user-side security measures.

CVE ID Title CVSS Severity Published
CVE-2026-101081 D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow — DI-8400 CWE-121 9.1 Critical 2026-09-28
CVE-2026-100740 D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write — DIR-895L CWE-787 9.9 Critical 2026-09-27
CVE-2026-96891 D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write — DIR-825 CWE-787 9.8 Critical 2026-09-24
CVE-2026-95675 D-Link DAP-1360 6.14 Unauthenticated RCE via Web Management Interface — DAP-1360 CWE-78 9.8 Critical 2026-09-22
CVE-2026-94089 D-Link DIR-868L Authentication webfa_authentication.cgi strcpy stack-based overflow — DIR-868L CWE-121 10.0 Critical 2026-09-20
CVE-2026-94050 D-Link DIR-X1860Z ubus JSON-RPC interface routerd.get_rand_key information disclosure — DIR-X1860Z CWE-200 4.3 Medium 2026-09-20
CVE-2026-94036 D-Link DIR-X1860/DIR-X1860Z routerd ubus access control — DIR-X1860 CWE-284 8.8 High 2026-09-20
CVE-2026-93958 D-Link R95 DHMAPI ssi system os command injection — R95 CWE-78 9.1 Critical 2026-09-20
CVE-2026-91003 D-Link DI-8300 CGI Service rzgl.asp rzgl_asp stack-based overflow — DI-8300 CWE-121 9.1 Critical 2026-09-15
CVE-2026-91001 D-Link DI-8400 DDNS Configuration ddns.asp ddns_asp stack-based overflow — DI-8400 CWE-121 9.9 Critical 2026-09-15
CVE-2026-90881 D-Link DIR-882 CGI Binary dllog.cgi main information disclosure — DIR-882 CWE-200 5.3 Medium 2026-09-15
CVE-2026-90880 D-Link DSL-3782 Diagnostics Diagnostics.asp system command injection — DSL-3782 CWE-77 7.4 High 2026-09-15
CVE-2026-90706 D-Link DWR-M921 formWsc os command injection — DWR-M921 CWE-78 6.6 Medium 2026-09-14
CVE-2026-90705 D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection — DWR-M921 CWE-78 6.6 Medium 2026-09-14
CVE-2026-90704 D-Link DWR-M921 formDiskPartition system command injection — DWR-M921 CWE-77 6.6 Medium 2026-09-14
CVE-2026-90703 D-Link DWR-M921 formDiskCreateShare system os command injection — DWR-M921 CWE-78 9.1 Critical 2026-09-14
CVE-2026-90702 D-Link DWR-M921 formDiskFormat system os command injection — DWR-M921 CWE-78 9.1 Critical 2026-09-14
CVE-2026-90699 D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection — DWR-M920 CWE-78 9.9 Critical 2026-09-14
CVE-2026-90693 D-Link DIR-878 WAN Settings SetWan3Settings stack-based overflow — DIR-878 CWE-121 9.9 Critical 2026-09-14
CVE-2026-90692 D-Link DIR-878 Dynamic DNS IPv6 Settings SetDynamicDNSIPv6Settings stack-based overflow — DIR-878 CWE-121 9.9 Critical 2026-09-14
CVE-2026-90680 D-Link DIR-823G HNAP1 SetStaticRouteSettings strcpy stack-based overflow — DIR-823G CWE-121 9.9 Critical 2026-09-14
CVE-2026-86510 D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write — DIR-822A CWE-787 9.9 Critical 2026-09-08
CVE-2026-86509 D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow — DIR-895L CWE-121 9.6 Critical 2026-09-08
CVE-2026-86297 D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one — DIR-605 CWE-193 8.1 High 2026-09-07
CVE-2026-86296 D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow — DIR-822A CWE-121 10.0 Critical 2026-09-07
CVE-2026-86295 D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection — DIR-895L CWE-77 8.3 High 2026-09-07
CVE-2026-85224 D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection — DNS-320 ShareCenter CWE-78 9.1 Critical 2026-09-03
CVE-2026-85223 D-Link DNS-340L CGI dropbox.cgi os command injection — DNS-340L CWE-78 9.9 Critical 2026-09-03
CVE-2026-85222 D-Link DNS-340L Add-On Center addon_center.cgi os command injection — DNS-340L CWE-78 9.1 Critical 2026-09-03
CVE-2026-82692 D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection — DNS-340L CWE-78 9.9 Critical 2026-08-31

This page lists every published CVE security advisory associated with D-Link. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.