PatchSiren

D-Link CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited D-Link CVE published 2022-03-25

CVE-2019-16920

CVE-2019-16920 is a D-Link Multiple Routers command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-25. Because it is on the KEV list, organizations should treat it as actively exploited or at least high-risk in the wild and prioritize remediation. CISA’s stated guidance for the impacted product is that it is end-of-life and should be disconnected if still in use.

Known exploited D-Link CVE published 2022-03-25

CVE-2016-11021

CVE-2016-11021 is a D-Link DCS-930L device vulnerability described in official records as an OS command injection issue. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2022-03-25, which means it is treated as actively exploited in the wild. The KEV entry also states that the impacted product is end-of-life and should be disconnected if still in use.

Known exploited D-Link CVE published 2022-03-25

CVE-2013-5223

CVE-2013-5223 is a cross-site scripting issue affecting the D-Link DSL-2760U gateway and is included in CISA's Known Exploited Vulnerabilities catalog. For defenders, the practical takeaway is straightforward: treat this as an active remediation item, confirm whether any DSL-2760U devices are in use, and apply vendor updates as directed. The supplied corpus does not include a CVSS score, so prioritization [truncated]

Known exploited D-Link CVE published 2022-02-10

CVE-2015-2051

CVE-2015-2051 is a D-Link DIR-645 Router remote code execution vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2022-02-10. The impacted product is end-of-life, and CISA’s stated action is to disconnect it if it is still in use. In the supplied official record set, the safest remediation path is removal and replacement rather than relying on a patch.

Known exploited D-Link CVE published 2021-11-03

CVE-2020-29557

CVE-2020-29557 is a buffer overflow vulnerability affecting D-Link DIR-825 R1 devices. The most important risk signal in the supplied corpus is that CISA has included this CVE in the Known Exploited Vulnerabilities catalog, which means it should be treated as an actively exploited issue and prioritized for remediation. The available record does not provide technical exploitation details, a CVSS score, or [truncated]

Known exploited D-Link CVE published 2021-11-03

CVE-2020-25506

CVE-2020-25506 is a command injection vulnerability affecting the D-Link DNS-320 device. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2021-11-03, which is a strong signal that the issue has been exploited in the wild. The supplied sources do not provide deeper technical detail, but the KEV listing means this should be treated as a high-priority remediation item for any organizatio [truncated]

HIGH D Link CVE published 2017-03-06

CVE-2017-5633

CVE-2017-5633 is a HIGH-severity CSRF issue in the D-Link DI-524 Wireless Router firmware 9.01. According to NVD, crafted requests to CGI programs can let an attacker trigger admin-password changes, device reboots, and possibly other unspecified effects.