PatchSiren

D-Link CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL D-Link CVE published 2026-09-20

CVE-2026-94089

A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

MEDIUM D-Link CVE published 2026-09-20

CVE-2026-94050

A vulnerability was found in the D-Link DIR-X1860Z router, affecting its ubus JSON-RPC interface. This issue allows for information disclosure and requires local network access to exploit. The vulnerability is addressed in firmware version 1.0.7.260821.161908. The affected product is no longer supported by the maintainer, which may complicate mitigation efforts. Network administrators should assess exposu [truncated]

HIGH D-Link CVE published 2026-09-20

CVE-2026-94036

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. This vulnerability could allow attackers to bypass security controls, potentially leading t [truncated]

HIGH D-Link CVE published 2026-09-20

CVE-2026-93958

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. Defenders should assess exposure and prioritize verification of remote access configurations a [truncated]

HIGH D-Link CVE published 2026-09-08

CVE-2026-86509

A stack-based buffer overflow vulnerability has been identified in D-Link DIR-895L A1_102b07, specifically in the udhcpcd component. This issue, tracked as CVE-2026-86509, affects the sendOffer/sendACK functions within the udhcpcd/serverpacket.c file. The vulnerability can only be exploited within the local network. An exploit for this vulnerability has been made public.

HIGH D-Link CVE published 2026-09-07

CVE-2026-86297

A vulnerability was identified in D-Link DIR-605 B1v202WWB03, affecting the L2TP Control Message Parser. This issue is caused by an off-by-one error in the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c, which can be triggered by manipulating the peer_hostname argument. The attack may be performed remotely and is considered difficult to exploit. The exploit is publicly available.

CRITICAL D-Link CVE published 2026-09-07

CVE-2026-86296

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vulnerability has a significant impact on network security, and defenders [truncated]

MEDIUM D-Link CVE published 2026-09-07

CVE-2026-86295

A command injection vulnerability was found in D-Link DIR-895L A1_102b07 in the udhcpcd component. The vulnerability affects the sendACK function in udhcpcd/serverpacket.c and can be exploited remotely via the Hostname argument. The exploit has been made public. This vulnerability requires verification of exposure and vulnerability of udhcpcd components. Defenders should prioritize assessment and monitori [truncated]

HIGH D-Link CVE published 2026-08-31

CVE-2026-82690

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T12:17:57.977Z and has not been modified since then. The vulnerability, CVE-2026-82690, is an os command injection issue in D-Link DNS-327L and DNS-340L up to 20260717, affecting an unknown functionality of the file /cgi-bin/ve_mgr.cgi through manipulation of the argument f_dev. The attack is poss [truncated]

HIGH D-Link CVE published 2026-08-31

CVE-2026-82689

CVE-2026-82689 is a vulnerability detected in D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to 20260717. The vulnerability affects an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler, allowing for OS command injection via manipulation of the upIsoRootPath argument. This can be exploited remotely. Organizations should prioritize patching to prevent potential r [truncated]

HIGH D-Link CVE published 2026-08-31

CVE-2026-82688

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T11:16:40.353Z and has not been modified since then. The CVE-2026-82688 vulnerability is an os command injection vulnerability in the Virtual Volume Handler component of D-Link DNS-340L and DNS-345 devices. The vulnerability affects the /cgi-bin/virtual_vol.cgi file and allows remote attackers to [truncated]

HIGH D-Link CVE published 2026-08-31

CVE-2026-82680

A weakness has been identified in D-Link DSM-G600 1.01, specifically in the /load_file.cgi file of the Multipart Handler component. This vulnerability could lead to an out-of-bounds write, allowing for potential remote attacks. The CVE record was published on 2026-08-31T11:16:40.177Z and has not been modified since then. The CVSS score is 7.4, indicating a high severity. System administrators and security [truncated]

LOW D-Link CVE published 2026-08-31

CVE-2026-82595

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T00:16:41.980Z and has not been modified since then. The vulnerability affects D-Link DIR-825M 1.1.8, specifically in the function sub_456CF4 of the file /boafrm/formSysCmd, allowing for command injection via manipulation of the sysCmd argument. The attack can be initiated remotely. Security teams [truncated]

HIGH D-Link CVE published 2026-08-30

CVE-2026-82592

A vulnerability was detected in D-Link DIR-825M 1.1.8, specifically in the sub_46725C function of the /boafrm/formDiskFormat endpoint, leading to a stack-based buffer overflow. This allows for remote exploitation and has a public exploit available. The CVSS score is 8.6, indicating high severity. Organizations should verify their inventory and apply remediation when available. The CVE record was published [truncated]

LOW D-Link CVE published 2026-08-15

CVE-2026-19893

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T12:16:32.543Z and has not been modified since then. The vulnerability affects D-Link DIR-842 2.01.B04, specifically in the vsftpd component, leading to incorrect default permissions. The attack can be launched remotely with high complexity and difficult exploitability. The CVSS score is 2.3 with [truncated]

CRITICAL D-Link CVE published 2026-08-08

CVE-2026-71951

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.570Z and has not been modified since then. CVE-2026-71951 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formIMEISetup interface, allowing remote [truncated]

CRITICAL D‑Link CVE published 2026-08-08

CVE-2026-71949

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T17:16:48.267Z and has not been modified since then. CVE-2026-71949 is a critical command injection vulnerability in the /boafrm/formUSSDSetup interface of D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. A remote attacker can inject arbitrary mal [truncated]

CRITICAL D-Link CVE published 2026-08-08

CVE-2026-71948

CVE-2026-71948 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. The vulnerability exists in the /boafrm/formDebugDiagnosticRun interface, allowing remote attackers to inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. This vulnerability has a CVSS s [truncated]

MEDIUM D-Link CVE published 2026-07-21

CVE-2026-16447

A vulnerability has been found in D-Link DNS-320 1.0.2. The impacted component is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. This vulnerability has a CVSS score of 5.5 and is classified as MEDIU [truncated]

MEDIUM D-Link CVE published 2026-07-21

CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The vulnerability is caused by improper handling of the Malicious Handler argument, allowing for unrestricted upload. Users of D-Link DNS-320 1.0.2 [truncated]

MEDIUM D-Link CVE published 2026-07-21

CVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2, specifically in the /photo_center/php/uploadify.php file. The manipulation of the Malicious Handler argument leads to unrestricted upload. The attack may be initiated remotely. This vulnerability has a CVSS score of 5.5 and a MEDIUM severity. Users of D-Link DNS-320 1.0.2 should be aware of this vulnerability and take necessary precautions. The CVE r [truncated]

Review D-Link CVE published 2026-07-13

CVE-2026-52533

A vulnerability exists in D-Link DIR-1253 v.1.0.1.250923.142435 that allows an attacker to escalate privileges via the etc/shadow component file. The CVE record was published on 2026-07-13T22:16:48.020Z and has not been modified since then. This vulnerability is a privilege escalation issue that can be exploited by an attacker to gain elevated privileges. Users of D-Link DIR-1253 v.1.0.1.250923.142435 sho [truncated]

MEDIUM D-link CVE published 2026-07-09

CVE-2026-15270

A medium-severity vulnerability, CVE-2026-15270, has been identified in D-link DIR-823G 1.0.2B05_20181207. The vulnerability affects an unknown functionality of the file /etc/boa/boa.conf in the Web Interface, potentially leading to least privilege violation. The attack can be launched remotely but requires a high level of complexity. Security teams should assess the potential impact on their networks and [truncated]

HIGH D-Link CVE published 2026-06-13

CVE-2026-12174

A high-severity vulnerability, CVE-2026-12174, has been detected in D-Link DCS-935L 1.10.01. The issue affects the snprintf function in the /web/cgi-bin/greece/rhea file of the HTTP Handler component. This vulnerability is caused by manipulation of the 'data' argument, leading to a format string vulnerability. The attack can be launched remotely, and the exploit has been publicly disclosed.

LOW D-Link CVE published 2026-06-08

CVE-2026-11555

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult.

MEDIUM D-Link CVE published 2026-06-08

CVE-2026-11497

CVE-2026-11497 is a medium severity vulnerability in D-Link DCS-5615 1.01.00. The vulnerability affects an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver, allowing for least privilege violation. The attack can be executed remotely and has been disclosed to the public.

LOW D-Link CVE published 2026-06-08

CVE-2026-11492

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05, specifically in the vsftpd component. This flaw leads to a least privilege violation and can be exploited remotely. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 2.1, indicating a low severity.

LOW D-Link CVE published 2026-06-05

CVE-2026-11341

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely.

LOW D-Link CVE published 2026-06-05

CVE-2026-11339

A command injection vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

LOW D-Link CVE published 2026-06-05

CVE-2026-10878

A low-severity vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. The function sub_41C8E8 of the file /boafrm/formSmsManage is affected, allowing for command injection through manipulation of the argument action_value. The attack can be carried out remotely. For more information, refer to [resourceLinkAnnotations id='ref-4'] and [resourceLinkAnnotations id='nvd'].