VulnSea

dlink has 52 CVEs on record between 2021 and 2026. Disclosures have slowed: 0 in the last 90 days after 32 in the 90 before. The busiest recent month was April 2026 with 31. The median CVSS is 7.5 (high), with 6 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-120 (24) and CWE-121 (10). Most affected products: di-8003_firmware (27), dir-2640-us_firmware (4), di-8300_firmware (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—(1)
Last 90 days
0 prev 32

Products

  • di-8003_firmware 27
  • dir-2640-us_firmware 4
  • di-8300_firmware 3
  • dir-823g_firmware 3
  • dir-x1860_firmware 3
  • dsl-3782_firmware 2
52
Total CVEs
6
Critical
1
CISA KEV
1
Exploited

dlink vulnerabilities

CVEs affecting dlink, newest first. Open any entry for full detail, references, and exploit status.

52 CVEsRSS

CVE-2025-45058High· 7.5
5mo ago

D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function

D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ Twilightdlink · di-8300_firmwareEPSS 0.40%via NVD
CVE-2025-45057High· 7.5
5mo ago

D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function

D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ Twilightdlink · di-8300_firmwareEPSS 0.40%via NVD
CVE-2026-5213High· 8.8
6mo ago

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1…

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1…

▾ Twilightdlink · dnr-202l_firmwareEPSS 1.2%via NVD
CVE-2025-15391Medium· 6.3
9mo ago

A weakness has been identified in D-Link DIR-806A 100CNb11

A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has be…

▾ Sunlitdlink · dir-806a_firmwareEPSS 4.2%via NVD
CVE-2025-45729Medium· 6.3
1y ago

D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

D-Link DIR-823-Pro 1.02 has improper permission control, allowing unauthorized users to turn on and access Telnet services.

▾ Sunlitdlink · dir-823_pro_firmwareEPSS 0.37%via NVD
CVE-2022-35192High· 7.5
4y ago

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via the User parameter or Pwd parameter to Login.asp.

▾ Twilightdlink · dsl-3782_firmwareEPSS 1.0%via NVD
CVE-2021-42627Critical· 9.8PoC
4y ago

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the dat…

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the dat…

▾ Abyssaldlink · dir-615_firmwareEPSS 63%via NVD
CVE-2022-35191Medium· 6.5
4y ago

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

D-Link Wireless AC1200 Dual Band VDSL ADSL Modem Router DSL-3782 Firmware v1.01 allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted HTTP connection request.

▾ Sunlitdlink · dsl-3782_firmwareEPSS 1.0%via NVD
CVE-2022-36526High· 7.5
4y ago

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.

▾ Twilightdlink · go-rt-ac750_firmwareEPSS 1.2%via NVD
CVE-2022-36524High· 7.5
4y ago

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

▾ Twilightdlink · go-rt-ac750_firmwareEPSS 0.86%via NVD
CVE-2022-28932Critical· 9.8
4y ago

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

▾ Midnightdlink · dsl-g2452dg_firmwareEPSS 1.2%via NVD
CVE-2022-26258Critical· 9.8CISA KEV
4y ago

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

▾ Hadaldlink · dir-820l_firmwareEPSS 92%via NVD
CVE-2021-41445Medium· 6.1
4y ago

A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated …

A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated …

▾ Sunlitdlink · dir-x1860_firmwareEPSS 1.9%via NVD
CVE-2021-41442High· 7.5
4y ago

An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

▾ Twilightdlink · dir-x1860_firmwareEPSS 3.7%via NVD
CVE-2021-41441High· 7.4
4y ago

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to…

▾ Twilightdlink · dir-x1860_firmwareEPSS 1.7%via NVD
CVE-2020-25366Critical· 9.1
4y ago

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

▾ Midnightdlink · dir-823g_firmwareEPSS 2.5%via NVD
CVE-2020-25367Critical· 9.8
4y ago

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.

▾ Midnightdlink · dir-823g_firmwareEPSS 8.6%via NVD
CVE-2020-25368Critical· 9.8
4y ago

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05

A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.

▾ Midnightdlink · dir-823g_firmwareEPSS 8.6%via NVD
CVE-2021-34204Medium· 6.8
5y ago

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials

D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all dev…

▾ Sunlitdlink · dir-2640-us_firmwareEPSS 1.1%via NVD
CVE-2021-34203High· 8.1
5y ago

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password…

▾ Twilightdlink · dir-2640-us_firmwareEPSS 1.2%via NVD
CVE-2021-34201High· 7.1
5y ago

D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow

D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, caus…

▾ Twilightdlink · dir-2640-us_firmwareEPSS 0.54%via NVD
CVE-2021-34202High· 7.8
5y ago

There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04

There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be elevated to administrator permissions, resulting in local arbitrary code execution. An attacker can combin…

▾ Twilightdlink · dir-2640-us_firmwareEPSS 3.6%via NVD
dlink vulnerabilities (CVEs) — page 2 · VulnSea