Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

D-Link — Vulnerabilities & Security Advisories 825

Browse all 825 CVE security advisories affecting D-Link. AI-powered Chinese analysis, POCs, and references for each vulnerability.

D-Link manufactures networking hardware, primarily consumer-grade routers and wireless access points, serving as a critical infrastructure component for home and small business internet connectivity. The company’s product line has historically been plagued by significant security deficiencies, resulting in 760 recorded Common Vulnerabilities and Exposures. These flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from hardcoded credentials or unpatched firmware updates. A notable incident occurred in 2017 when a critical vulnerability allowed attackers to gain administrative control over millions of devices, facilitating large-scale botnet recruitment. The persistent lack of timely security patches and weak default configurations have established a pattern of neglect, leaving users exposed to persistent threats. This track record highlights systemic issues in the development and maintenance lifecycle of D-Link’s network equipment, necessitating rigorous user-side security measures.

CVE ID Title CVSS Severity Published
CVE-2026-82691 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection — DNS-320L CWE-78 9.1 Critical 2026-08-31
CVE-2026-82690 D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection — DNS-327L CWE-78 9.1 Critical 2026-08-31
CVE-2026-82689 D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection — DNS-320L CWE-78 9.9 Critical 2026-08-31
CVE-2026-82688 D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection — DNS-340L CWE-78 9.1 Critical 2026-08-31
CVE-2026-82680 D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write — DSM-G600 CWE-787 8.8 High 2026-08-31
CVE-2026-82595 D-Link DIR-825M System Command Execution formSysCmd sub_456CF4 command injection — DIR-825M CWE-77 7.4 High 2026-08-30
CVE-2026-82593 D-Link DIR-825M LTE Module Firmware Upgrade formLtefotaUpgradeFibocom sub_41802C stack-based overflow — DIR-825M CWE-121 9.9 Critical 2026-08-30
CVE-2026-82592 D-Link DIR-825M Disk Formatting Handler Endpoint formDiskFormat sub_46725C stack-based overflow — DIR-825M CWE-121 9.9 Critical 2026-08-30
CVE-2026-19893 D-Link DIR-842 vsftpd vsftpd.conf default permission — DIR-842 CWE-276 3.1 Low 2026-08-15
CVE-2026-16448 D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection — DNS-120 CWE-77 6.3 Medium 2026-07-21
CVE-2026-16447 D-Link DNS-320 multi_uploadify.php unrestricted upload — DNS-320 CWE-434 7.3 High 2026-07-21
CVE-2026-16332 D-Link DNS-320 multi_uploadify.php unrestricted upload — DNS-320 CWE-434 7.3 High 2026-07-21
CVE-2026-16331 D-Link DNS-320 save_ajax.php unrestricted upload — DNS-320 CWE-434 7.3 High 2026-07-21
CVE-2026-16330 D-Link DNS-320 uploadify.php unrestricted upload — DNS-320 CWE-434 7.3 High 2026-07-21
CVE-2026-16329 D-Link DNS-320 uploadify.php unrestricted upload — DNS-320 CWE-434 7.3 High 2026-07-21
CVE-2026-16327 D-Link DNS-320 upload.php unrestricted upload — DNS-320 CWE-434 7.3 High 2026-07-20
CVE-2026-15270 D-link DIR-823G Web boa.conf least privilege violation — DIR-823G CWE-272 7.5 High 2026-07-09
CVE-2026-13545 D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection — DCS-935L CWE-78 8.8 High 2026-06-29
CVE-2026-12174 D-Link DCS-935L HTTP rhea snprintf format string — DCS-935L CWE-134 8.8 High 2026-06-13
CVE-2026-11555 D-Link DGS-1100-08PD Web boa.conf least privilege violation — DGS-1100-08PD CWE-272 3.7 Low 2026-06-08
CVE-2026-11497 D-Link DCS-5615 Boa Webserver boa.conf least privilege violation — DCS-5615 CWE-272 5.3 Medium 2026-06-08
CVE-2026-11492 D-Link DIR-823G vsftpd vsftpd.conf least privilege violation — DIR-823G CWE-272 4.3 Medium 2026-06-08
CVE-2026-11341 D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection — DWR-M920 CWE-78 6.3 Medium 2026-06-05
CVE-2026-11339 D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection — DWR-M920 CWE-77 6.3 Medium 2026-06-05
CVE-2026-10878 D-Link DWR-M920 formSmsManage sub_41C8E8 command injection — DWR-M920 CWE-77 6.3 Medium 2026-06-05
CVE-2026-10270 D-Link DI-7001 MINI API httpd_debug.asp sprintf stack-based overflow — DI-7001 MINI CWE-121 8.8 High 2026-06-01
CVE-2026-10206 D-Link DI-8400 dbsrv.asp stack-based overflow — DI-8400 CWE-121 8.8 High 2026-06-01
CVE-2018-25358 D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi — DIR-601 CWE-497 7.5 High 2026-05-23
CVE-2026-8346 D-Link DIR-816 portForward command injection — DIR-816 CWE-77 6.3 Medium 2026-05-11
CVE-2026-8345 D-Link DIR-816 singlePortForward sub_445E7C command injection — DIR-816 CWE-77 6.3 Medium 2026-05-11

This page lists every published CVE security advisory associated with D-Link. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.