VulnSea

dlink has 51 CVEs on record between 2021 and 2026. Disclosures have slowed: 0 in the last 90 days after 33 in the 90 before. The busiest recent month was April 2026 with 31. The median CVSS is 7.5 (high), with 6 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-120 (24) and CWE-121 (10). Most affected products: di-8003_firmware (27), dir-2640-us_firmware (4), di-8300_firmware (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.5
Publish → KEV
(1)
Last 90 days
0 prev 33

Products

  • di-8003_firmware 27
  • dir-2640-us_firmware 4
  • di-8300_firmware 3
  • dir-823g_firmware 3
  • dir-x1860_firmware 3
  • dsl-3782_firmware 2
51
Total CVEs
6
Critical
1
CISA KEV
1
Exploited

dlink vulnerabilities

CVEs affecting dlink, newest first. Open any entry for full detail, references, and exploit status.

51 CVEsRSS

CVE-2026-8260High· 8.8
4mo ago

A vulnerability was found in D-Link DCS-935L up to 1.10.01

A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword r…

Twilightdlink · dcs-935l_firmwareEPSS 1.00%via NVD
CVE-2025-50673High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50672High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50671High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively l…

Twilightdlink · di-8003_firmwareEPSS 0.49%via NVD
CVE-2025-50670High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_bwr.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in the name, qq, a…

Twilightdlink · di-8003_firmwareEPSS 0.49%via NVD
CVE-2025-50669High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50668High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50667High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.41%via NVD
CVE-2025-50666High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parame…

Twilightdlink · di-8003_firmwareEPSS 0.60%via NVD
CVE-2025-50665High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the n…

Twilightdlink · di-8003_firmwareEPSS 0.60%via NVD
CVE-2025-50664High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters…

Twilightdlink · di-8003_firmwareEPSS 0.60%via NVD
CVE-2025-50663High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50662High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50661High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with para…

Twilightdlink · di-8003_firmwareEPSS 0.60%via NVD
CVE-2025-50660High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50659High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50657High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50655High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50654High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50653High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50652High· 7.5
5mo ago

An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.

An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.47%via NVD
CVE-2025-50650High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50649High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50648High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50647High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50646High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50645High· 7.5
5mo ago

A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated

A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value fo…

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-50644High· 7.5
5mo ago

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.

Twilightdlink · di-8003_firmwareEPSS 0.52%via NVD
CVE-2025-52222High· 7.5
5mo ago

D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffe…

D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffe…

Twilightdlink · di-8100_firmwareEPSS 0.33%via NVD
CVE-2025-45059High· 7.5
5mo ago

D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function

D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

Twilightdlink · di-8300_firmwareEPSS 0.40%via NVD
dlink vulnerabilities (CVEs) · VulnSea