Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

D-Link — Vulnerabilities & Security Advisories 825

Browse all 825 CVE security advisories affecting D-Link. AI-powered Chinese analysis, POCs, and references for each vulnerability.

D-Link manufactures networking hardware, primarily consumer-grade routers and wireless access points, serving as a critical infrastructure component for home and small business internet connectivity. The company’s product line has historically been plagued by significant security deficiencies, resulting in 760 recorded Common Vulnerabilities and Exposures. These flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from hardcoded credentials or unpatched firmware updates. A notable incident occurred in 2017 when a critical vulnerability allowed attackers to gain administrative control over millions of devices, facilitating large-scale botnet recruitment. The persistent lack of timely security patches and weak default configurations have established a pattern of neglect, leaving users exposed to persistent threats. This track record highlights systemic issues in the development and maintenance lifecycle of D-Link’s network equipment, necessitating rigorous user-side security measures.

CVE ID Title CVSS Severity Published
CVE-2025-9938 D-Link DI-8400 yyxz.asp yyxz_dlink_asp stack-based overflow — DI-8400 CWE-121 8.8 High 2025-09-03
CVE-2025-9769 D-Link DI-7400G+ mng_platform.asp sub_478D28 command injection — DI-7400G+ CWE-77 4.1 Medium 2025-09-01
CVE-2025-9752 D-Link DIR-852 SOAP Service soap.cgi soapcgi_main os command injection — DIR-852 CWE-78 7.3 High 2025-09-01
CVE-2025-9745 D-Link DI-500WF jhttpd version_upgrade.asp os command injection — DI-500WF CWE-78 4.7 Medium 2025-08-31
CVE-2025-9727 D-Link DIR-816L soap.cgi soapcgi_main os command injection — DIR-816L CWE-78 6.3 Medium 2025-08-31
CVE-2018-25115 D-Link DIR-110/412/600/615/645/815 RCE via service.cgi — DIR-110 CWE-78 9.8AI Critical AI 2025-08-27
CVE-2025-9026 D-Link DIR-860L Simple Service Discovery Protocol cgibin ssdpcgi_main os command injection — DIR-860L CWE-78 7.3 High 2025-08-15
CVE-2025-9003 D-Link DIR-818LW DHCP Reserved Address bsc_lan.php cross site scripting — DIR-818LW CWE-79 3.5 Low 2025-08-15
CVE-2025-8978 D-Link DIR-619L boa FirmwareUpgrade data authenticity — DIR-619L CWE-345 6.6 Medium 2025-08-14
CVE-2025-8956 D-Link DIR‑818L ssdpcgi cgibin getenv command injection — DIR‑818L CWE-77 6.3 Medium 2025-08-14
CVE-2025-8949 D-Link DIR-825 httpd ping_response.cgi get_ping_app_stat stack-based overflow — DIR-825 CWE-121 7.2 High 2025-08-14
CVE-2013-10069 D-Link Devices Unauthenticated RCE — DIR-600 rev B CWE-78 9.8AI Critical AI 2025-08-05
CVE-2013-10048 D-Link Devices command.php Unauthenticated RCE — DIR-600 CWE-78 9.8 - 2025-08-01
CVE-2013-10050 D-Link Devices tools_vct.xgi Authenticated RCE — DIR-300 rev A CWE-78 8.8 - 2025-08-01
CVE-2013-10059 D-Link Routers tools_vct.htm OS Command Injection — DIR-615H1 CWE-78 8.8 - 2025-08-01
CVE-2012-10021 D-Link DIR-605L Captcha Handling Buffer Overflow — DIR-605L CWE-121 9.8AI Critical AI 2025-07-31
CVE-2025-8231 D-Link DIR-890L UART Port rgbin hard-coded credentials — DIR-890L CWE-798 6.8 Medium 2025-07-27
CVE-2025-8184 D-Link DIR-513 HTTP POST Request formSetWanL2TPtriggers formSetWanL2TPcallback stack-based overflow — DIR-513 CWE-121 8.8 High 2025-07-26
CVE-2025-8175 D-Link DI-8400 jhttpd usb_paswd.asp null pointer dereference — DI-8400 CWE-476 6.5 Medium 2025-07-26
CVE-2025-8169 D-Link DIR-513 HTTP POST Request formSetWanPPTPpath formSetWanPPTPcallback buffer overflow — DIR-513 CWE-120 8.8 High 2025-07-25
CVE-2025-8168 D-Link DIR-513 formSetWanPPPoE websAspInit buffer overflow — DIR-513 CWE-120 8.8 High 2025-07-25
CVE-2014-125117 D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE — DSP-W215 CWE-121 9.8 - 2025-07-25
CVE-2025-8159 D-Link DIR-513 HTTP POST Request formLanguageChange stack-based overflow — DIR-513 CWE-121 8.8 High 2025-07-25
CVE-2025-8155 D-Link DCS-6010L Management Application vb.htm cross site scripting — DCS-6010L CWE-79 3.5 Low 2025-07-25
CVE-2025-7945 D-Link DIR-513 formSetWanDhcpplus buffer overflow — DIR-513 CWE-120 8.8 High 2025-07-21
CVE-2025-7932 D-Link DIR‑817L ssdpcgi lxmldbc_system command injection — DIR‑817L CWE-77 6.3 Medium 2025-07-21
CVE-2025-7911 D-Link DI-8100 jhttpd upnp_ctrl.asp sprintf stack-based overflow — DI-8100 CWE-121 8.8 High 2025-07-20
CVE-2025-7910 D-Link DIR-513 Boa Webserver formSetWanNonLogin sprintf stack-based overflow — DIR-513 CWE-121 8.8 High 2025-07-20
CVE-2025-7909 D-Link DIR-513 Boa Webserver formLanSetupRouterSettings sprintf stack-based overflow — DIR-513 CWE-121 8.8 High 2025-07-20
CVE-2025-7908 D-Link DI-8100 jhttpd ddns.asp sprintf stack-based overflow — DI-8100 CWE-121 8.8 High 2025-07-20

This page lists every published CVE security advisory associated with D-Link. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.