Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

D-Link — Vulnerabilities & Security Advisories 825

Browse all 825 CVE security advisories affecting D-Link. AI-powered Chinese analysis, POCs, and references for each vulnerability.

D-Link manufactures networking hardware, primarily consumer-grade routers and wireless access points, serving as a critical infrastructure component for home and small business internet connectivity. The company’s product line has historically been plagued by significant security deficiencies, resulting in 760 recorded Common Vulnerabilities and Exposures. These flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from hardcoded credentials or unpatched firmware updates. A notable incident occurred in 2017 when a critical vulnerability allowed attackers to gain administrative control over millions of devices, facilitating large-scale botnet recruitment. The persistent lack of timely security patches and weak default configurations have established a pattern of neglect, leaving users exposed to persistent threats. This track record highlights systemic issues in the development and maintenance lifecycle of D-Link’s network equipment, necessitating rigorous user-side security measures.

CVE ID Title CVSS Severity Published
CVE-2025-4343 D-Link DIR-600L formEasySetupWizard buffer overflow — DIR-600L CWE-120 8.8 High 2025-05-06
CVE-2025-4342 D-Link DIR-600L formEasySetupWizard3 buffer overflow — DIR-600L CWE-120 8.8 High 2025-05-06
CVE-2025-4341 D-Link DIR-880L Request Header ssdpcgi sub_16570 command injection — DIR-880L CWE-77 6.3 Medium 2025-05-06
CVE-2025-4340 D-Link DIR-890L/DIR-806A1 soap.cgi sub_175C8 command injection — DIR-890L CWE-77 6.3 Medium 2025-05-06
CVE-2025-3785 D-Link DWR-M961 Authorization Interface formStaticDHCP stack-based overflow — DWR-M961 CWE-121 8.8 High 2025-04-18
CVE-2025-3538 D-Link DI-8100 jhttpd auth.asp auth_asp stack-based overflow — DI-8100 CWE-121 8.8 High 2025-04-13
CVE-2025-2717 D-Link DIR-823X HTTP POST Request diag_nslookup sub_41710C os command injection — DIR-823X CWE-78 4.7 Medium 2025-03-24
CVE-2025-2621 D-Link DAP-1620 storage check_dws_cookie stack-based overflow — DAP-1620 CWE-121 9.8 Critical 2025-03-22
CVE-2025-2620 D-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow — DAP-1620 CWE-121 9.8 Critical 2025-03-22
CVE-2025-2619 D-Link DAP-1620 Cookie storage check_dws_cookie stack-based overflow — DAP-1620 CWE-121 9.8 Critical 2025-03-22
CVE-2025-2618 D-Link DAP-1620 Path api set_ws_action heap-based overflow — DAP-1620 CWE-122 9.8 Critical 2025-03-22
CVE-2025-2553 D-Link DIR-618/DIR-605L formVirtualServ access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2552 D-Link DIR-618/DIR-605L formTcpipSetup access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2551 D-Link DIR-618/DIR-605L formSetPortTr access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2550 D-Link DIR-618/DIR-605L DDNS Service formSetDDNS access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2549 D-Link DIR-618/DIR-605L formSetPassword access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2548 D-Link DIR-618/DIR-605L formSetDomainFilter access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2547 D-Link DIR-618/DIR-605L formAdvNetwork access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2546 D-Link DIR-618/DIR-605L Firewall Service formAdvFirewall access control — DIR-618 CWE-284 4.3 Medium 2025-03-20
CVE-2025-2360 D-Link DIR-823G UPnP Service HNAP1 SetUpnpSettings improper authorization — DIR-823G CWE-285 7.3 High 2025-03-17
CVE-2025-2359 D-Link DIR-823G DDNS Service HNAP1 SetDDNSSettings improper authorization — DIR-823G CWE-285 7.3 High 2025-03-17
CVE-2025-1877 D-Link DAP-1562 HTTP POST Request pure_auth_check null pointer dereference — DAP-1562 CWE-476 6.5 Medium 2025-03-03
CVE-2025-1876 D-Link DAP-1562 HTTP Header http_request_parse stack-based overflow — DAP-1562 CWE-121 7.3 High 2025-03-03
CVE-2025-1800 D-Link DAR-7000 HTTP POST Request sxh_vpnlic.php get_ip_addr_details command injection — DAR-7000 CWE-77 6.3 Medium 2025-03-01
CVE-2025-1539 D-Link DAP-1320 storagein.pd-XXXXXX replace_special_char stack-based overflow — DAP-1320 CWE-121 8.8 High 2025-02-21
CVE-2025-1538 D-Link DAP-1320 api set_ws_action heap-based overflow — DAP-1320 CWE-122 8.8 High 2025-02-21
CVE-2025-1392 D-Link DIR-816 index.html cross site scripting — DIR-816 CWE-79 3.5 Low 2025-02-17
CVE-2025-1104 D-Link DHP-W310AV authentication spoofing — DHP-W310AV CWE-290 7.3 High 2025-02-07
CVE-2025-1103 D-Link DIR-823X HTTP POST Request set_wifi_blacklists null pointer dereference — DIR-823X CWE-476 6.5 Medium 2025-02-07
CVE-2025-0492 D-Link DIR-823X FUN_00412244 null pointer dereference — DIR-823X CWE-476 7.5 High 2025-01-15

This page lists every published CVE security advisory associated with D-Link. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.