PatchSiren

D-Link CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH D-Link CVE published 2026-04-08

CVE-2025-50647

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint. This vulnerability could allow an attacker to execute arbitrary code on the device. The CVE record was published on 2026-04-08T19:24:15.460Z and has not been modified since then. Security teams and administrators responsible for D-Link DI-8003 devices should be a [truncated]

HIGH D‑Link CVE published 2026-04-08

CVE-2025-50646

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue may allow an attacker to execute arbitrary code. Users of D-Link DI-8003 16.07.26A1 should be aware of this vulnerability and take necessary precautions to p [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50645

A high-severity buffer overflow vulnerability was discovered in D-Link DI-8003 16.07.26A1. The vulnerability occurs when the 's' parameter in the 'pppoe_list_opt.asp' endpoint is manipulated. By sending a crafted request with an excessively large value for the 's' parameter, an attacker can trigger a buffer overflow condition. This vulnerability has significant implications for organizations using the aff [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-50644

A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. This issue may allow an attacker to execute arbitrary code. Affected users should apply patches or updates as recommended by the vendor. The vulnerability is caused by a lack of proper input valida [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-52222

A buffer overflow vulnerability was discovered in various D-Link devices, including DI-8003, DI-8500, DI-8003G, DI-8200G, DI-8200, DI-8400, DI-8004w, DI-8100, and DI-8100G. The vulnerability exists in the radius_asp function and can be exploited via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters. This allows attackers to cause a Denial of Service (DoS) via a crafted [truncated]

HIGH D-Link CVE published 2026-04-08

CVE-2025-45058

A high-severity buffer overflow vulnerability was discovered in D-Link DI-8300 v16.07.26A1. The vulnerability exists in the jingx_asp function and can be exploited via a crafted input, potentially leading to a Denial of Service (DoS). Security teams should review the official advisory and CVE record for affected scope, severity, and vendor guidance.

HIGH D‑Link CVE published 2026-04-08

CVE-2025-45057

CVE-2025-45057 is a high-severity buffer overflow vulnerability in D-Link DI-8300 v16.07.26A1. The vulnerability is caused by a buffer overflow via the ip parameter in the ip_position_asp function, which allows attackers to cause a Denial of Service (DoS) via a crafted input. The CVSS score for this vulnerability is 7.5, indicating a high severity. The CVE record was published on 2026-04-08T18:24:45.597Z [truncated]

HIGH D-Link CVE published 2026-03-31

CVE-2026-5212

A vulnerability has been found in multiple D-Link devices up to 20260205. This issue affects the function Webdav_Upload_File of the file /cgi-bin/webdav_mgr.cgi. The manipulation of the argument f_file leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This vulnerability allows for remote exploitation and could lead to unauthorized access or control of the device.

HIGH D-Link CVE published 2026-03-31

CVE-2026-5211

A stack-based buffer overflow vulnerability exists in the UPnP functionality of multiple D-Link DNS products. The vulnerability is caused by improper handling of the f_dir argument in the UPnP_AV_Server_Path_Del function of the /cgi-bin/app_mgr.cgi file. This allows remote unauthenticated attackers to execute arbitrary code on affected devices. The affected products include D-Link DNS-120, DNR-202L, DNS-3 [truncated]

HIGH D-Link CVE published 2026-02-26

CVE-2025-71057

The CVE record indicates that CVE-2025-71057 is related to improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00. This vulnerability allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user. The CVSS score is 8.2, indicating a high severity. This vulnerability can be exploited by attackers to gain unauthorized access to [truncated]

Known exploited D-Link CVE published 2025-12-08

CVE-2022-37055

CVE-2022-37055 is a D-Link router buffer overflow issue that CISA added to its Known Exploited Vulnerabilities catalog on 2025-12-08. That placement means the issue is considered actively exploited in the wild, so remediation should be treated as urgent. The supplied corpus does not include affected model details or exploit conditions, so validation should come from D-Link and the official CVE/NVD records.

Known exploited D-Link CVE published 2025-08-05

CVE-2022-40799

CVE-2022-40799 is a D-Link DNR-322L vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. For defenders, the main takeaway is operational: treat any exposed DNR-322L deployment as urgent to assess, mitigate, or retire. The source corpus does not provide a CVSS score or detailed exploit mechanics, so the safest response is to follow vendor guidance, apply any available mitigati [truncated]

Known exploited D-Link CVE published 2025-08-05

CVE-2020-25079

CISA added CVE-2020-25079 to the Known Exploited Vulnerabilities catalog on 2025-08-05 for D-Link DCS-2530L and DCS-2670L devices. The listed vulnerability is a command injection issue, and CISA directs organizations to apply vendor mitigations or discontinue use if mitigations are unavailable.

Known exploited D-Link CVE published 2025-08-05

CVE-2020-25078

CVE-2020-25078 affects D-Link DCS-2530L and DCS-2670L devices and is described in the supplied corpus only as an unspecified vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-05, with a remediation due date of 2025-08-26. Because it is KEV-listed, defenders should treat it as a priority exposure even though the public description here does not provide deeper technical detail.

HIGH D-Link CVE published 2025-08-01

CVE-2013-10050

CVE-2013-10050 is a high-severity OS command injection vulnerability affecting multiple D-Link routers, specifically confirmed on DIR-300 revision A with firmware version 1.05 and DIR-615 revision D with firmware version 4.13. The vulnerability resides in the authenticated tools_vct.xgi CGI endpoint, where the pingIp parameter fails to properly sanitize user-supplied input. Attackers with valid credential [truncated]

Known exploited D-Link CVE published 2025-06-25

CVE-2024-0769

CVE-2024-0769 is a path traversal vulnerability affecting the D-Link DIR-859 Router and is listed by CISA in the Known Exploited Vulnerabilities catalog. That KEV listing means CISA considers it actively exploited in the wild. Organizations that still use this model should treat it as a high-priority remediation item and follow the vendor’s guidance referenced by CISA.

Known exploited D-Link CVE published 2024-09-30

CVE-2023-25280

CVE-2023-25280 is an OS command injection vulnerability affecting the D-Link DIR-820 Router. CISA added it to the Known Exploited Vulnerabilities catalog, and the supplied KEV metadata says the product is end-of-life/end-of-service, so the practical response is to retire it rather than wait for a patch.

Known exploited D-Link CVE published 2024-05-16

CVE-2021-40655

CVE-2021-40655 is an information disclosure vulnerability associated with the D-Link DIR-605 router family. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-05-16, and CISA’s guidance says the affected hardware revisions are end-of-life or end-of-service and should be retired and replaced. For organizations that still have DIR-605 devices in service, this is a priority asset-removal an [truncated]

Known exploited D-Link CVE published 2024-05-16

CVE-2014-100005

CVE-2014-100005 is a cross-site request forgery vulnerability affecting the D-Link DIR-600 router and is included in CISA's Known Exploited Vulnerabilities catalog. CISA notes that associated hardware revisions have reached end-of-life or end-of-service and should be retired and replaced per vendor instructions.

Known exploited D-Link CVE published 2024-04-11

CVE-2024-3273

CVE-2024-3273 is a command injection vulnerability affecting D-Link multiple NAS devices. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2024-04-11, which indicates active exploitation concern. The source guidance is especially important for defenders because the affected hardware revisions are described as legacy products that have reached end-of-life or end-of-service status, wit [truncated]

Known exploited D-Link CVE published 2024-04-11

CVE-2024-3272

CVE-2024-3272 is a hard-coded credentials vulnerability affecting D-Link Multiple NAS Devices. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-04-11, which signals known exploitation risk. The KEV notice states the affected hardware revisions are legacy D-Link products that have reached end-of-life or end-of-service and should be retired and replaced per vendor instructions.

Known exploited D-Link CVE published 2024-01-08

CVE-2016-20017

CVE-2016-20017 is a command injection vulnerability affecting D-Link DSL-2750B devices and is listed by CISA in the Known Exploited Vulnerabilities catalog. Because it is identified as known exploited, defenders should treat exposure as urgent and follow vendor mitigation guidance or discontinue use if mitigations are not available.

Known exploited D-Link CVE published 2023-06-29

CVE-2019-20500

CVE-2019-20500 is a command injection vulnerability affecting the D-Link DWL-2600AP Access Point. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-29, which means it should be treated as actively exploited or confirmed exploitable in the wild. The source corpus does not provide a CVSS score, so defenders should rely on exploitation status and asset exposure when prioritizing respons [truncated]

Known exploited D-Link CVE published 2023-06-29

CVE-2019-17621

CISA’s Known Exploited Vulnerabilities catalog lists CVE-2019-17621 as a command execution vulnerability affecting the D-Link DIR-859 Router. Because it is on the KEV list, defenders should treat it as urgent and follow vendor remediation guidance. If a fix is not available for the affected deployment, CISA advises discontinuing use of the product.

Known exploited D-Link CVE published 2022-09-08

CVE-2022-26258

CVE-2022-26258 is a remote code execution vulnerability affecting the D-Link DIR-820L. CISA has added it to the Known Exploited Vulnerabilities catalog, and the KEV entry says the impacted product is end-of-life and should be disconnected if still in use.

Known exploited D-Link CVE published 2022-09-08

CVE-2018-6530

CVE-2018-6530 is a D-Link multiple-routers OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-09-08. CISA also notes vendor guidance stating that the fix under CVE-2018-20114 properly patches this KEV entry. Because CISA lists known ransomware campaign use, affected D-Link routers should be prioritized for vendor-recommended remediation or removal fro [truncated]

Known exploited D-Link CVE published 2022-09-08

CVE-2011-4723

CVE-2011-4723 is a D-Link DIR-300 router issue described as cleartext storage of a password. It is also listed in CISA’s Known Exploited Vulnerabilities catalog, which makes it a defensive priority even though the supplied corpus does not provide deeper technical detail. CISA’s guidance in the KEV entry says the impacted product is end-of-life and should be disconnected if still in use.

Known exploited D-Link CVE published 2022-04-15

CVE-2019-16057

CVE-2019-16057 is a remote code execution vulnerability affecting the D-Link DNS-320 storage device. CISA added it to the Known Exploited Vulnerabilities catalog, indicating active exploitation risk, and the KEV entry also notes known ransomware campaign use. Because the impacted product is end-of-life, CISA’s guidance is to disconnect it if it is still in use.

Known exploited D-Link CVE published 2022-04-04

CVE-2021-45382

CVE-2021-45382 is a remote code execution vulnerability affecting D-Link Multiple Routers. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2022-04-04, which means defenders should treat it as actively exploited or at least a priority for urgent remediation. CISA’s guidance for the impacted product is especially direct: the device family is end-of-life and should be disconnected if still in use.

Known exploited D-Link CVE published 2022-03-25

CVE-2020-9377

CVE-2020-9377 is a D-Link DIR-610 device remote command execution issue that CISA lists in its Known Exploited Vulnerabilities catalog. The CISA entry identifies the impacted product as end-of-life and states that it should be disconnected if still in use. For defenders, this is an urgent exposure-management item rather than a routine patch cycle update.