Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

D-Link — Vulnerabilities & Security Advisories 825

Browse all 825 CVE security advisories affecting D-Link. AI-powered Chinese analysis, POCs, and references for each vulnerability.

D-Link manufactures networking hardware, primarily consumer-grade routers and wireless access points, serving as a critical infrastructure component for home and small business internet connectivity. The company’s product line has historically been plagued by significant security deficiencies, resulting in 760 recorded Common Vulnerabilities and Exposures. These flaws frequently involve remote code execution, cross-site scripting, and privilege escalation, often stemming from hardcoded credentials or unpatched firmware updates. A notable incident occurred in 2017 when a critical vulnerability allowed attackers to gain administrative control over millions of devices, facilitating large-scale botnet recruitment. The persistent lack of timely security patches and weak default configurations have established a pattern of neglect, leaving users exposed to persistent threats. This track record highlights systemic issues in the development and maintenance lifecycle of D-Link’s network equipment, necessitating rigorous user-side security measures.

CVE ID Title CVSS Severity Published
CVE-2026-8344 D-Link DIR-816 formDMZ.cgi sub_445E7C command injection — DIR-816 CWE-77 6.3 Medium 2026-05-11
CVE-2026-8273 D-Link DNS-320 system_mgr.cgi cgi_merge_user os command injection — DNS-320 CWE-78 4.7 Medium 2026-05-11
CVE-2026-8272 D-Link DNS-320 webfile_mgr.cgi chown os command injection — DNS-320 CWE-78 4.7 Medium 2026-05-11
CVE-2026-8271 D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection — DNS-320 CWE-78 4.7 Medium 2026-05-11
CVE-2026-8260 D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow — DCS-935L CWE-120 8.8 High 2026-05-11
CVE-2026-7857 D-Link DI-8100 CGI user_group.asp sprintf buffer overflow — DI-8100 CWE-120 7.2 High 2026-05-05
CVE-2026-7856 D-Link DI-8100 Web Management url_member.asp buffer overflow — DI-8100 CWE-120 7.2 High 2026-05-05
CVE-2026-7855 D-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflow — DI-8100 CWE-120 8.8 High 2026-05-05
CVE-2026-7854 D-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow — DI-8100 CWE-120 9.8 Critical 2026-05-05
CVE-2026-7853 D-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow — DI-8100 CWE-120 9.8 Critical 2026-05-05
CVE-2026-7851 D-Link DI-8100 yyxz.asp sprintf stack-based overflow — DI-8100 CWE-121 7.2 High 2026-05-05
CVE-2026-42376 D-Link DIR-456U A1 Hardcoded Telnet Backdoor Credentials — DIR-456U Firmware CWE-798 9.8 Critical 2026-05-04
CVE-2026-42375 D-Link DIR-600L A1 Hardcoded Telnet Backdoor Credentials — DIR-600L Firmware CWE-798 9.8 Critical 2026-05-04
CVE-2026-42374 D-Link DIR-600L B1 Hardcoded Telnet Backdoor Credentials — DIR-600L Firmware CWE-798 9.8 Critical 2026-05-04
CVE-2026-42373 D-Link DIR-605L B2 Hardcoded Telnet Backdoor Credentials — DIR-605L Firmware CWE-798 9.8 Critical 2026-05-04
CVE-2026-42372 D-Link DIR-605L A1 Hardcoded Telnet Backdoor Credentials — DIR-605L Firmware CWE-798 8.8 High 2026-05-04
CVE-2026-7554 D-Link M60 httpd password recovery — M60 CWE-640 5.6 Medium 2026-05-01
CVE-2026-7289 D-Link DIR-825M formWanConfigSetup sub_414BA8 buffer overflow — DIR-825M CWE-120 8.8 High 2026-04-28
CVE-2026-7288 D-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow — DIR-825M CWE-120 8.8 High 2026-04-28
CVE-2026-7248 D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow — DI-8100 CWE-120 9.8 Critical 2026-04-28
CVE-2026-7247 D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow — DI-8100 CWE-120 7.2 High 2026-04-28
CVE-2026-7069 D-Link DIR-825 miniupnpd upnpsoap.c AddPortMapping buffer overflow — DIR-825 CWE-120 8.0 High 2026-04-27
CVE-2026-7068 D-Link DIR-825 nmbd sserver.c NMBD_process buffer overflow — DIR-825 CWE-120 8.8 High 2026-04-26
CVE-2026-7067 D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection — DIR-822 CWE-77 7.3 High 2026-04-26
CVE-2026-7027 D-Link DSL-2740R Wireless Setup Section cross site scripting — DSL-2740R CWE-79 2.4 Low 2026-04-26
CVE-2026-7026 D-Link DGS-3420 System Information Settings cross site scripting — DGS-3420 CWE-79 4.5 Medium 2026-04-26
CVE-2026-6947 D-Link|DWM-222W USB Wi-Fi Adapter - Brute-Force Protection Bypass — DWM-222W CWE-307 7.5 High 2026-04-24
CVE-2026-6014 D-Link DIR-513 POST Request formAdvanceSetup buffer overflow — DIR-513 CWE-120 8.8 High 2026-04-10
CVE-2026-6013 D-Link DIR-513 POST Request formSetRoute buffer overflow — DIR-513 CWE-120 8.8 High 2026-04-10
CVE-2026-6012 D-Link DIR-513 POST Request formSetPassword buffer overflow — DIR-513 CWE-120 8.8 High 2026-04-10

This page lists every published CVE security advisory associated with D-Link. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.