target entity

D-Link

26 source-linked records in the current knowledge graph.

high

CVE-2025-29635: D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-29635EPSS 87.2%D-LinkDIR-823X
CISA KEV ↗ · unattributed attribution
high

CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability

D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-37055EPSS 57.0%D-LinkRouters
CISA KEV ↗ · unattributed attribution
high

CVE-2020-25078: D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25078EPSS 97.9%D-LinkDCS-2530L and DCS-2670L Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2020-25079: D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2020-25079EPSS 52.7%D-LinkDCS-2530L and DCS-2670L Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2022-40799: D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2022-40799EPSS 31.3%D-LinkDNR-322L
CISA KEV ↗ · unattributed attribution
high

CVE-2024-0769: D-Link DIR-859 Router Path Traversal Vulnerability

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-0769EPSS 82.7%D-LinkDIR-859 Router
CISA KEV ↗ · unattributed attribution · 2 IOCs
high

CVE-2023-25280: D-Link DIR-820 Router OS Command Injection Vulnerability

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2023-25280EPSS 98.1%D-LinkDIR-820 Router
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2021-40655: D-Link DIR-605 Router Information Disclosure Vulnerability

D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2021-40655EPSS 87.0%D-LinkDIR-605 Router
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-100005: D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2014-100005EPSS 42.4%D-LinkDIR-600 Router
CISA KEV ↗ · unattributed attribution
high

CVE-2024-3273: D-Link Multiple NAS Devices Command Injection Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2024-3272CVE-2024-3273EPSS 100.0%D-LinkMultiple NAS Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2024-3272: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution. Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CVE-2024-3272EPSS 98.0%D-LinkMultiple NAS Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerability

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2016-20017EPSS 60.4%D-LinkDSL-2750B Devices
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-17621: D-Link DIR-859 Router Command Execution Vulnerability

D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2019-17621EPSS 89.6%D-LinkDIR-859 Router
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-20500: D-Link DWL-2600AP Access Point Command Injection Vulnerability

D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2019-20500EPSS 97.1%D-LinkDWL-2600AP Access Point
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-26258: D-Link DIR-820L Remote Code Execution Vulnerability

D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2022-26258EPSS 81.1%D-LinkDIR-820L
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-6530: D-Link Multiple Routers OS Command Injection Vulnerability

Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands. Required action: The vendor D-Link published an advisory stating the fix under CVE-2018-20114 properly patches KEV entry CVE-2018-6530. If the device is still supported, apply updates per vendor instructions. If the affected device has since entered its end-of-life, it should be disconnected if still in use.

CVE-2018-20114CVE-2018-6530EPSS 96.7%D-LinkMultiple Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2015-2051: D-Link DIR-645 Router Remote Code Execution Vulnerability

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2015-2051EPSS 97.1%D-LinkDIR-645 Router
CISA KEV ↗ · unattributed attribution