Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

D-Link — Vulnerabilities & Security Advisories 825

Browse all 825 CVE security advisories affecting D-Link. AI-powered Chinese analysis, POCs, and references for each vulnerability.

D-Link manufactures networking hardware, primarily consumer-grade routers and wireless access points, serving as a critical infrastructure component for home and small business internet connectivity. The company’s product line has historically been plagued by significant security deficiencies, resulting in 760 recorded Common Vulnerabilities and Exposures. These flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from hardcoded credentials or unpatched firmware updates. A notable incident occurred in 2017 when a critical vulnerability allowed attackers to gain administrative control over millions of devices, facilitating large-scale botnet recruitment. The persistent lack of timely security patches and weak default configurations have established a pattern of neglect, leaving users exposed to persistent threats. This track record highlights systemic issues in the development and maintenance lifecycle of D-Link’s network equipment, necessitating rigorous user-side security measures.

CVE ID Title CVSS Severity Published
CVE-2025-0481 D-Link DIR-878 HTTP POST Request dllog.cgi information disclosure — DIR-878 CWE-200 5.3 Medium 2025-01-15
CVE-2024-13108 D-Link DIR-816 A2 form2NetSniper.cgi access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13107 D-Link DIR-816 A2 ACL form2LocalAclEditcfg.cgi access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13106 D-Link DIR-816 A2 IP QoS form2IPQoSTcAdd access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13105 D-Link DIR-816 A2 DHCPD Setting form2Dhcpd.cgi access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13104 D-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13103 D-Link DIR-816 A2 Virtual Service form2AddVrtsrv.cgi access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13102 D-Link DIR-816 A2 DDNS Service access control — DIR-816 A2 CWE-284 5.3 Medium 2025-01-02
CVE-2024-13030 D-Link DIR-823G Web Management Interface HNAP1 SetVirtualServerSettings access control — DIR-823G CWE-284 7.3 High 2024-12-30
CVE-2024-11960 D-Link DIR-605L formSetPortTr buffer overflow — DIR-605L CWE-120 8.8 High 2024-11-28
CVE-2024-11959 D-Link DIR-605L formResetStatistic buffer overflow — DIR-605L CWE-120 8.8 High 2024-11-28
CVE-2024-11068 D-Link DSL6740C - Incorrect Use of Privileged APIs — DSL6740C CWE-648 9.8 Critical 2024-11-11
CVE-2024-11067 D-Link DSL6740C - Arbitrary File Reading through Path Traversal — DSL6740C CWE-23 7.5 High 2024-11-11
CVE-2024-11066 D-Link DSL6740C - OS Command Injection — DSL6740C CWE-78 7.2 High 2024-11-11
CVE-2024-11065 D-Link DSL6740C - OS Command Injection — DSL6740C CWE-78 7.2 High 2024-11-11
CVE-2024-11064 D-Link DSL6740C - OS Command Injection — DSL6740C CWE-78 7.2 High 2024-11-11
CVE-2024-11063 D-Link DSL6740C - OS Command Injection — DSL6740C CWE-78 7.2 High 2024-11-11
CVE-2024-11062 D-Link DSL6740C - OS Command Injection — DSL6740C CWE-78 7.2 High 2024-11-11
CVE-2024-11048 D-Link DI-8003 dbsrv.asp dbsrv_asp stack-based overflow — DI-8003 CWE-121 8.8 High 2024-11-10
CVE-2024-11047 D-Link DI-8003 upgrade_filter.asp upgrade_filter_asp stack-based overflow — DI-8003 CWE-121 8.8 High 2024-11-10
CVE-2024-11046 D-Link DI-8003 upgrade_filter.asp upgrade_filter_asp os command injection — DI-8003 CWE-78 6.3 Medium 2024-11-10
CVE-2024-10916 D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L HTTP GET Request info.xml information disclosure — DNS-320 CWE-200 5.3 Medium 2024-11-06
CVE-2024-10915 D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection — DNS-320 CWE-78 8.1 High 2024-11-06
CVE-2024-10914 D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection — DNS-320 CWE-78 8.1 High 2024-11-06
CVE-2024-9915 D-Link DIR-619L B1 formVirtualServ buffer overflow — DIR-619L B1 CWE-120 8.8 High 2024-10-13
CVE-2024-9914 D-Link DIR-619L B1 formSetWizardSelectMode buffer overflow — DIR-619L B1 CWE-120 8.8 High 2024-10-13
CVE-2024-9913 D-Link DIR-619L B1 formSetRoute buffer overflow — DIR-619L B1 CWE-120 8.8 High 2024-10-13
CVE-2024-9912 D-Link DIR-619L B1 formSetQoS buffer overflow — DIR-619L B1 CWE-120 8.8 High 2024-10-13
CVE-2024-9911 D-Link DIR-619L B1 formSetPortTr buffer overflow — DIR-619L B1 CWE-120 8.8 High 2024-10-13
CVE-2024-9910 D-Link DIR-619L B1 formSetPassword buffer overflow — DIR-619L B1 CWE-120 8.8 High 2024-10-13

This page lists every published CVE security advisory associated with D-Link. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.