D-Link has 23 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 22 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 22. The median CVSS is 9.1 (critical), with 13 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-119 (9) and CWE-77 (9). Most affected products: DWR-M921 (5), DIR-822A (2), DIR-878 (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 22 prev 0
Products
- DWR-M921 5
- DIR-822A 2
- DIR-878 2
- DIR-895L 2
- DI-8300 1
- DI-8400 1
Worst active — by depth score
CVE-2026-91001Critical· 9.9A security flaw has been discovered in D-Link DI-8400 16.0767CVE-2026-90699Critical· 9.9A weakness has been identified in D-Link DWR-M920 1.1.767CVE-2026-90693Critical· 9.9A flaw has been found in D-Link DIR-878 120B0567CVE-2026-86510Critical· 9.9A vulnerability has been found in D-Link DIR-822A A_10167CVE-2026-86296Critical· 10.0A vulnerability was determined in D-Link DIR-822A A_10167
D-Link vulnerabilities
CVEs affecting D-Link, newest first. Open any entry for full detail, references, and exploit status.
23 CVEsRSS
CVE-2026-94089Critical· 10.0A vulnerability was determined in D-Link DIR-868L 2.01b05
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…
CVE-2026-94050Medium· 4.3A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402
A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure.…
CVE-2026-94036High· 8.8PoCA security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results…
CVE-2026-93958Critical· 9.1PoCA vulnerability was found in D-Link R95 BE9500_1.00.16
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…
CVE-2026-91003Critical· 9.1PoCA flaw has been found in D-Link DI-8300 16.07
A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exp…
CVE-2026-91001Critical· 9.9PoCA security flaw has been discovered in D-Link DI-8400 16.07
A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip resul…
CVE-2026-90881Medium· 5.3PoCA weakness has been identified in D-Link DIR-882 up to 20260814
A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launc…
CVE-2026-90880High· 7.4PoCA security flaw has been discovered in D-Link DSL-3782 2016-07-28
A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…
CVE-2026-90704Medium· 6.6PoCA vulnerability was found in D-Link DWR-M921 1.1.52
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…
CVE-2026-90703Critical· 9.1PoCA vulnerability has been found in D-Link DWR-M921 1.1.52
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be …
CVE-2026-90680Critical· 9.9A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/…
CVE-2026-90702Critical· 9.1PoCA flaw has been found in D-Link DWR-M921 1.1.52
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…
CVE-2026-90693Critical· 9.9PoCA flaw has been found in D-Link DIR-878 120B05
A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the a…
CVE-2026-90692Critical· 9.9A vulnerability was detected in D-Link DIR-878 120B05
A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer ov…
CVE-2026-90705Medium· 6.6PoCA vulnerability was determined in D-Link DWR-M921 1.1.52
A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command inj…
CVE-2026-90699Critical· 9.9PoCA weakness has been identified in D-Link DWR-M920 1.1.7
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…
CVE-2026-90706Medium· 6.6PoCA vulnerability was identified in D-Link DWR-M921 1.1.52
A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried ou…
CVE-2026-86510Critical· 9.9PoCA vulnerability has been found in D-Link DIR-822A A_101
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The ex…
CVE-2026-86509Critical· 9.6PoCA flaw has been found in D-Link DIR-895L A1_102b07
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be don…
CVE-2026-86297High· 8.1PoCA vulnerability was identified in D-Link DIR-605 B1v202WWB03
A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argumen…
CVE-2026-86296Critical· 10.0PoCA vulnerability was determined in D-Link DIR-822A A_101
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is poss…
CVE-2026-86295High· 8.3PoCA vulnerability was found in D-Link DIR-895L A1_102b07
A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can…
CVE-2021-33259Medium· 5.3Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.