VulnSea

d-link has 24 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 23 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 23. The median CVSS is 9.1 (critical), with 14 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-119 (9) and CWE-77 (9). Most affected products: DWR-M921 (5), DIR-822A (2), DIR-878 (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.1
Publish → KEV
Last 90 days
23 prev 0

Products

  • DWR-M921 5
  • DIR-822A 2
  • DIR-878 2
  • DIR-895L 2
  • DAP-1360 1
  • DI-8300 1
24
Total CVEs
14
Critical
0
CISA KEV
0
Exploited

d-link vulnerabilities

CVEs affecting d-link, newest first. Open any entry for full detail, references, and exploit status.

24 CVEsRSS

CVE-2026-95675Critical· 9.8PoC
yesterday

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…

AbyssalD-LINK · DAP-1360via NVD
CVE-2026-94089Critical· 10.0PoC
3d ago

A vulnerability was determined in D-Link DIR-868L 2.01b05

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lea…

AbyssalD-Link · DIR-868LEPSS 0.98%via NVD
CVE-2026-94050Medium· 4.3
3d ago

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402

A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure.…

SunlitD-Link · DIR-X1860ZEPSS 0.23%via NVD
CVE-2026-94036High· 8.8PoC
3d ago

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results…

MidnightD-Link · DIR-X1860EPSS 0.47%via NVD
CVE-2026-93958Critical· 9.1PoC
3d ago

A vulnerability was found in D-Link R95 BE9500_1.00.16

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…

AbyssalD-Link · R95EPSS 2.2%via NVD
CVE-2026-91003Critical· 9.1PoC
1w ago

A flaw has been found in D-Link DI-8300 16.07

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exp…

AbyssalD-Link · DI-8300EPSS 0.51%via NVD
CVE-2026-91001Critical· 9.9PoC
1w ago

A security flaw has been discovered in D-Link DI-8400 16.07

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip resul…

AbyssalD-Link · DI-8400EPSS 0.48%via NVD
CVE-2026-90881Medium· 5.3PoC
1w ago

A weakness has been identified in D-Link DIR-882 up to 20260814

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launc…

TwilightD-Link · DIR-882EPSS 0.41%via NVD
CVE-2026-90880High· 7.4PoC
1w ago

A security flaw has been discovered in D-Link DSL-3782 2016-07-28

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…

MidnightD-Link · DSL-3782EPSS 1.0%via NVD
CVE-2026-90704Medium· 6.6PoC
1w ago

A vulnerability was found in D-Link DWR-M921 1.1.52

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitatio…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-90703Critical· 9.1PoC
1w ago

A vulnerability has been found in D-Link DWR-M921 1.1.52

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be …

AbyssalD-Link · DWR-M921EPSS 2.8%via NVD
CVE-2026-90680Critical· 9.9
1w ago

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/…

MidnightD-Link · DIR-823GEPSS 0.51%via NVD
CVE-2026-90702Critical· 9.1PoC
1w ago

A flaw has been found in D-Link DWR-M921 1.1.52

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…

AbyssalD-Link · DWR-M921EPSS 2.8%via NVD
CVE-2026-90693Critical· 9.9PoC
1w ago

A flaw has been found in D-Link DIR-878 120B05

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the a…

AbyssalD-Link · DIR-878EPSS 0.47%via NVD
CVE-2026-90692Critical· 9.9
1w ago

A vulnerability was detected in D-Link DIR-878 120B05

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer ov…

MidnightD-Link · DIR-878EPSS 0.47%via NVD
CVE-2026-90705Medium· 6.6PoC
1w ago

A vulnerability was determined in D-Link DWR-M921 1.1.52

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command inj…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-90699Critical· 9.9PoC
1w ago

A weakness has been identified in D-Link DWR-M920 1.1.7

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…

AbyssalD-Link · DWR-M920EPSS 1.6%via NVD
CVE-2026-90706Medium· 6.6PoC
1w ago

A vulnerability was identified in D-Link DWR-M921 1.1.52

A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried ou…

TwilightD-Link · DWR-M921EPSS 1.5%via NVD
CVE-2026-86510Critical· 9.9PoC
2w ago

A vulnerability has been found in D-Link DIR-822A A_101

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The ex…

AbyssalD-Link · DIR-822AEPSS 0.46%via NVD
CVE-2026-86509Critical· 9.6PoC
2w ago

A flaw has been found in D-Link DIR-895L A1_102b07

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be don…

AbyssalD-Link · DIR-895LEPSS 0.43%via NVD
CVE-2026-86297High· 8.1PoC
2w ago

A vulnerability was identified in D-Link DIR-605 B1v202WWB03

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argumen…

MidnightD-Link · DIR-605EPSS 1.0%via NVD
CVE-2026-86296Critical· 10.0PoC
2w ago

A vulnerability was determined in D-Link DIR-822A A_101

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is poss…

AbyssalD-Link · DIR-822AEPSS 1.3%via NVD
CVE-2026-86295High· 8.3PoC
2w ago

A vulnerability was found in D-Link DIR-895L A1_102b07

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can…

MidnightD-Link · DIR-895LEPSS 1.7%via NVD
CVE-2021-33259Medium· 5.3
4y ago

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

Sunlitd-link · dir-868lw_firmwareEPSS 1.8%via NVD
d-link vulnerabilities (CVEs) · VulnSea