PatchSiren

D-Link CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL D-Link CVE published 2026-08-08

CVE-2026-71951

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.570Z and has not been modified since then. CVE-2026-71951 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formIMEISetup interface, allowing remote [truncated]

CRITICAL D‑Link CVE published 2026-08-08

CVE-2026-71949

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.267Z and has not been modified since then. CVE-2026-71949 is a critical command injection vulnerability in the /boafrm/formUSSDSetup interface of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. A remote attacker can inject arbitrary mal [truncated]

CRITICAL D-Link CVE published 2026-08-08

CVE-2026-71948

CVE-2026-71948 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formDebugDiagnosticRun interface, allowing remote attackers to inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. This vulnerability has a CVSS s [truncated]

MEDIUM D-Link CVE published 2026-07-21

CVE-2026-16447

A vulnerability has been found in D-Link DNS-320 1.0.2. The impacted component is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. This vulnerability has a CVSS score of 5.5 and is classified as MEDIU [truncated]

MEDIUM D-Link CVE published 2026-07-21

CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The vulnerability is caused by improper handling of the Malicious Handler argument, allowing for unrestricted upload. Users of D-Link DNS-320 1.0.2 [truncated]

MEDIUM D-Link CVE published 2026-07-21

CVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2, specifically in the /photo_center/php/uploadify.php file. The manipulation of the Malicious Handler argument leads to unrestricted upload. The attack may be initiated remotely. This vulnerability has a CVSS score of 5.5 and a MEDIUM severity. Users of D-Link DNS-320 1.0.2 should be aware of this vulnerability and take necessary precautions. The CVE r [truncated]

Review D-Link CVE published 2026-07-13

CVE-2026-52533

A vulnerability exists in D-Link DIR-1253 v.1.0.1.250923.142435 that allows an attacker to escalate privileges via the etc/shadow component file. The CVE record was published on 2026-07-13T22:16:48.020Z and has not been modified since then. This vulnerability is a privilege escalation issue that can be exploited by an attacker to gain elevated privileges. Users of D-Link DIR-1253 v.1.0.1.250923.142435 sho [truncated]

MEDIUM D-link CVE published 2026-07-09

CVE-2026-15270

A medium-severity vulnerability, CVE-2026-15270, has been identified in D-link DIR-823G 1.0.2B05_20181207. The vulnerability affects an unknown functionality of the file /etc/boa/boa.conf in the Web Interface, potentially leading to least privilege violation. The attack can be launched remotely but requires a high level of complexity. Security teams should assess the potential impact on their networks and [truncated]

HIGH D-Link CVE published 2026-06-13

CVE-2026-12174

A high-severity vulnerability, CVE-2026-12174, has been detected in D-Link DCS-935L 1.10.01. The issue affects the snprintf function in the /web/cgi-bin/greece/rhea file of the HTTP Handler component. This vulnerability is caused by manipulation of the 'data' argument, leading to a format string vulnerability. The attack can be launched remotely, and the exploit has been publicly disclosed.

LOW D-Link CVE published 2026-06-08

CVE-2026-11555

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult.

MEDIUM D-Link CVE published 2026-06-08

CVE-2026-11497

CVE-2026-11497 is a medium severity vulnerability in D-Link DCS-5615 1.01.00. The vulnerability affects an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver, allowing for least privilege violation. The attack can be executed remotely and has been disclosed to the public.

LOW D-Link CVE published 2026-06-08

CVE-2026-11492

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05, specifically in the vsftpd component. This flaw leads to a least privilege violation and can be exploited remotely. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 2.1, indicating a low severity.

LOW D-Link CVE published 2026-06-05

CVE-2026-11341

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely.

LOW D-Link CVE published 2026-06-05

CVE-2026-11339

A command injection vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

LOW D-Link CVE published 2026-06-05

CVE-2026-10878

A low-severity vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. The function sub_41C8E8 of the file /boafrm/formSmsManage is affected, allowing for command injection through manipulation of the argument action_value. The attack can be carried out remotely. For more information, refer to [resourceLinkAnnotations id='ref-4'] and [resourceLinkAnnotations id='nvd'].

HIGH D-Link CVE published 2026-06-01

CVE-2026-10270

A stack-based buffer overflow vulnerability exists in the D-Link DI-7001 MINI router firmware up to version 19.09.19A1. The vulnerability is located in the `sprintf` function within the `/httpd_debug.asp` file, a component of the device's API. Manipulation of the `Time` argument can trigger the overflow condition. The attack vector is network-based and the exploit has been publicly disclosed, increasing t [truncated]

HIGH D-Link CVE published 2026-05-23

CVE-2018-25358

CVE-2018-25358 documents an unauthenticated credential disclosure vulnerability in D-Link DIR-601 firmware version 2.02NA. The flaw resides in the /my_cgi.cgi endpoint, which accepts a table_name parameter that can be manipulated to extract sensitive configuration data without authentication. Affected parameters include admin_user, wireless_settings, and wireless_security, which return administrative cred [truncated]

HIGH D-Link CVE published 2026-05-11

CVE-2026-8260

CVE-2026-8260 is a HIGH severity vulnerability in the D-Link DCS-935L HNAP Service. The vulnerability is caused by a buffer overflow in the SetDeviceSettings function of the /web/cgi-bin/hnap/hnap_service file. The attack can be executed remotely and has been made public. This vulnerability has significant implications for users of the affected product, as it could allow an attacker to execute arbitrary c [truncated]

HIGH D-Link CVE published 2026-05-05

CVE-2026-7857

A buffer overflow vulnerability was found in D-Link DI-8100 16.07.26A1, affecting the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. This vulnerability has been publicly disclosed and may be used by attackers. The vulnerability has a high impact on the system and requires immediate attention. Users [truncated]

HIGH D-Link CVE published 2026-05-05

CVE-2026-7856

A buffer overflow vulnerability was found in D-Link DI-8100 16.07.26A1. The issue affects an unknown part of the file /url_member.asp of the Web Management Interface. Executing a manipulation of the argument Name can lead to buffer overflow. The attack can be launched remotely. Network administrators and security teams should review the CVE record and vendor guidance for affected scope and severity.

HIGH D-Link CVE published 2026-05-05

CVE-2026-7855

A buffer overflow vulnerability was detected in D-Link DI-8100 16.07.26A1, specifically in the tggl_asp function of the /tggl.asp file within the HTTP Request Handler component. The vulnerability is triggered by manipulating the Name argument, leading to a buffer overflow. This issue can be exploited remotely, potentially allowing attackers to execute arbitrary code or disrupt service. Network administrat [truncated]

HIGH D-Link CVE published 2026-05-05

CVE-2026-7854

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T19:16:23.540Z and has not been modified since then. The NVD entry is currently Analyzed. This buffer overflow vulnerability in the url_rule_asp function of the /url_rule.asp file in D-Link DI-8100 16.07.26A1 can be exploited remotely through a POST parameter handler, posing a high severity risk w [truncated]

HIGH D-Link CVE published 2026-05-05

CVE-2026-7853

A weakness has been identified in D-Link DI-8100 16.07.26A1, specifically in the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes a buffer overflow, which can be exploited remotely. The exploit has been made available publicly and could be used for attacks. Users of D-Link DI-8100, especially those with exposure to the intern [truncated]

HIGH D-Link CVE published 2026-05-05

CVE-2026-7851

A stack-based buffer overflow vulnerability was identified in D-Link DI-8100 16.07.26A1, affecting the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to the vulnerability. The attack is possible to be carried out remotely. This CVE is of high severity with a CVSS score of 7.3. Network administrators and security teams should prioritize assessment and remediation efforts. [truncated]

HIGH D-Link CVE published 2026-04-24

CVE-2026-6947

CVE-2026-6947 is a HIGH severity (CVSS 8.7) authentication bypass vulnerability in the DWM-222W USB Wi-Fi Adapter developed by D-Link. The vulnerability allows unauthenticated adjacent network attackers to bypass brute-force protection mechanisms, enabling unlimited login attempts to gain unauthorized control over the device. The weakness is categorized as CWE-307 (Improper Restriction of Excessive Authen [truncated]

Known exploited D-Link CVE published 2026-04-24

CVE-2025-29635

CVE-2025-29635 is a D-Link DIR-823X command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-04-24. Because it is listed in KEV, defenders should treat it as a high-priority remediation item and follow vendor mitigation guidance or discontinue use of the product if mitigations are unavailable.

HIGH D-Link CVE published 2026-04-09

CVE-2026-5815

A stack-based buffer overflow vulnerability exists in the hedwigcgi_main function of the /cgi-bin/hedwig.cgi file in D-Link DIR-645 versions 1.01, 1.02, and 1.03. This issue allows remote attackers to exploit the vulnerability. The exploit is now public and may be used. However, detailed information about the exploit and its impact is limited. The vulnerability only affects products that are no longer sup [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50672

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE record was published on 2026-04-08T19:24:17.913Z and has not been modified since then. Users of D-Link DI-8003 16.07.26A1 should assess and potentially apply vendor remediation.

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50671

CVE-2025-50671 is a HIGH severity vulnerability in D-Link DI-8003 16.07.26A1. The vulnerability exists due to improper handling of parameters in the /xwgl_ref.asp endpoint, allowing for a buffer overflow. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with excessively long strings in parameters. This vulnerability has a high CVSS score of 7.5, indicating a significant ris [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50670

CVE-2025-50670 is a HIGH severity vulnerability in D-Link DI-8003 16.07.26A1. The vulnerability exists due to improper handling of parameters in the /xwgl_bwr.asp endpoint, allowing an attacker to exploit it by sending a crafted HTTP GET request. This could lead to potential code execution or denial of service. Users of D-Link DI-8003 16.07.26A1 should apply patches or mitigations to prevent exploitation. [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50669

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parameter in the /wan_ping.asp endpoint. This HIGH severity vulnerability, with a CVSS score of 7.5, could allow attackers to execute arbitrary code or cause a denial of service. The CVE record was published on 2026-04-08T19:24:17.580Z and has not been modified since then. S [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50667

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detection.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue affects users of the D-Link DI-8003 16.07.26A1 product. The vulnerability allows for potential remote code execution. Users should review the official CVE record [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50664

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr. This issue has a CVSS score of 7.5 and is classified as HIGH severity. Security teams should review the official CVE and NVD records for detaile [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50663

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint. This HIGH severity vulnerability, with a CVSS score of 7.5, poses a significant risk to organizations using the affected device. The vulnerability's impact is primarily related to potential remote code execution or denial-of-service attacks. Security teams shou [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50662

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue affects users of the D-Link DI-8003 16.07.26A1 product. Users should review the official advisory and CVE record for affected scope and vendor guidance.

HIGH D-Link CVE published 2026-04-08

CVE-2025-50661

CVE-2025-50661 is a buffer overflow vulnerability in D-Link DI-8003 16.07.26A1. The vulnerability exists due to improper handling of multiple parameters in the /url_rule.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, en, ips, u, time, act, rpri, and log. This vulnerability has a high impact on affected systems, and security teams should [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50660

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint. This vulnerability has a high severity with a CVSS score of 7.5. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary precautions. The CVE record was published on 2026-04-08T19:24:16.583Z and has not been modified since t [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50659

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint. The CVE record was published on 2026-04-08T19:24:16.470Z and has not been modified since then. This vulnerability could allow an attacker to execute arbitrary code on the device, posing a significant risk to affected systems. Security teams should assess the [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50657

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue can lead to potential exploitation, allowing attackers to execute arbitrary code. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary pre [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50655

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint. This vulnerability could allow an attacker to execute arbitrary code on the device. The CVE record was published on 2026-04-08T19:24:16.257Z and has not been modified since then. Security teams should assess and mitigate this vulnerability to prevent potential attacks.

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50653

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue could allow an attacker to execute arbitrary code on the device. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary preca [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50652

A HIGH severity vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the id parameter in the /saveparm_usb.asp endpoint. This vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The weakness is related to CWE-120. Security teams and administrators responsible for D-Link DI-8003 devices should be [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50650

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint. This HIGH severity vulnerability has a CVSS score of 7.5. It could allow for arbitrary code execution if exploited. Security teams and administrators should be aware of this vulnerability and take necessary actions to mitigate the risk. [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50649

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This vulnerability could allow an attacker to execute arbitrary code on the device. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take neces [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50648

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. This issue may allow an attacker to execute arbitrary code. Affected users should apply patches or updates as recommended by the vendor. The vulnerability is caused by inadequate input validation in the /tggl. [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50647

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint. This vulnerability could allow an attacker to execute arbitrary code on the device. The CVE record was published on 2026-04-08T19:24:15.460Z and has not been modified since then. Security teams and administrators responsible for D-Link DI-8003 devices should be a [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50646

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue may allow an attacker to execute arbitrary code. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary precautions to p [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50645

A high-severity buffer overflow vulnerability was discovered in D-Link DI-8003 16.07.26A1. The vulnerability occurs when the 's' parameter in the 'pppoe_list_opt.asp' endpoint is manipulated. By sending a crafted request with an excessively large value for the 's' parameter, an attacker can trigger a buffer overflow condition. This vulnerability has significant implications for organizations using the aff [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50644

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue may allow an attacker to execute arbitrary code. Affected users should apply patches or updates as recommended by the vendor. The vulnerability is caused by a lack of proper input valida [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-52222

A buffer overflow vulnerability was discovered in various D-Link devices, including DI-8003, DI-8500, DI-8003G, DI-8200G, DI-8200, DI-8400, DI-8004w, DI-8100, and DI-8100G. The vulnerability exists in the radius_asp function and can be exploited via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters. This allows attackers to cause a Denial of Service (DoS) via a crafted [truncated]