Vendor
D-Link
As of , 26 D-Link vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 1 was added in 2026. Patch first: CVE-2015-2051.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2015-2051Remote Code Execution | D-Link DIR-645 Router | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 2 | CVE-2016-20017Command Injection | D-Link DSL-2750B Devices | Patch this weekMetasploit module; EPSS 0.64 | 0.64 | ||
| 3 | CVE-2019-17621Command Execution | D-Link DIR-859 Router | Patch this weekMetasploit module; EPSS 0.90 | 0.90 | ||
| 4 | CVE-2016-11021OS Command Injection | D-Link DCS-930L Devices | Patch this weekMetasploit module; EPSS 0.69 | 0.69 | ||
| 5 | CVE-2014-100005Cross-Site Request Forgery (CSRF) | D-Link DIR-600 Router | Patch this weekMetasploit module | 0.43 | ||
| 6 | CVE-2025-29635Command Injection | D-Link DIR-823X | Patch this weekEPSS 0.88 | 0.88 | ||
| 7 | CVE-2022-37055Buffer Overflow | D-Link Routers | Patch this weekEPSS 0.56 | 0.56 | ||
| 8 | CVE-2020-25078Unspecified | D-Link DCS-2530L and DCS-2670L Devices | Patch this weekEPSS 0.98 | 0.98 | ||
| 9 | CVE-2024-0769Path Traversal | D-Link DIR-859 Router | Patch this weekEPSS 0.83 | 0.83 | ||
| 10 | CVE-2023-25280OS Command Injection | D-Link DIR-820 Router | Patch this weekEPSS 0.98 | 0.98 | ||
| 11 | CVE-2021-40655Information Disclosure | D-Link DIR-605 Router | Patch this weekEPSS 0.87 | 0.87 | ||
| 12 | CVE-2024-3272Use of Hard-Coded Credentials | D-Link Multiple NAS Devices | Patch this weekEPSS 0.98 | 0.98 | ||
| 13 | CVE-2024-3273Command Injection | D-Link Multiple NAS Devices | Patch this weekEPSS 0.99 | 0.99 | ||
| 14 | CVE-2019-20500Command Injection | D-Link DWL-2600AP Access Point | Patch this weekEPSS 0.97 | 0.97 | ||
| 15 | CVE-2018-6530OS Command Injection | D-Link Multiple Routers | Patch this weekRansomware use; EPSS 0.97 | 0.97 | ||
| 16 | CVE-2022-26258Remote Code Execution | D-Link DIR-820L | Patch this weekEPSS 0.92 | 0.92 | ||
| 17 | CVE-2019-16057DNS-320 Remote Code Execution | D-Link DNS-320 Storage Device | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 18 | CVE-2021-45382Remote Code Execution | D-Link Multiple Routers | Patch this weekEPSS 0.98 | 0.98 | ||
| 19 | CVE-2019-16920Command Injection | D-Link Multiple Routers | Patch this weekEPSS 0.99 | 0.99 | ||
| 20 | CVE-2020-25506Command Injection | D-Link DNS-320 Device | Patch this weekEPSS 0.99 | 0.99 | ||
| 21 | CVE-2020-25079DCS-2530L and DCS-2670L Command Injection | D-Link DCS-2530L and DCS-2670L Devices | Patch this weekEPSS 0.54 | 0.54 | ||
| 22 | CVE-2013-5223Gateway Cross-Site Scripting | D-Link DSL-2760U | Patch this weekEPSS 0.51 | 0.51 | ||
| 23 | CVE-2020-29557Buffer Overflow | D-Link DIR-825 R1 Devices | Patch this weekEPSS 0.54 | 0.54 | ||
| 24 | CVE-2022-40799Download of Code Without Integrity Check | D-Link DNR-322L | Patch soon | 0.34 | ||
| 25 | CVE-2020-9377Remote Command Execution | D-Link DIR-610 Devices | Patch soon | 0.21 |
Products
- Multiple Routers3 entries
- DCS-2530L and DCS-2670L Devices2 entries
- DIR-859 Router2 entries
- Multiple NAS Devices2 entries
- DCS-930L Devices1 entry
- DIR-300 Router1 entry
- DIR-600 Router1 entry
- DIR-605 Router1 entry
- DIR-610 Devices1 entry
- DIR-645 Router1 entry
- DIR-820 Router1 entry
- DIR-820L1 entry
- DIR-823X1 entry
- DIR-825 R1 Devices1 entry
- DNR-322L1 entry
- DNS-320 Device1 entry
- DNS-320 Storage Device1 entry
- DSL-2750B Devices1 entry
- DSL-2760U1 entry
- DWL-2600AP Access Point1 entry
- Routers1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 2 |
| 2022 | 10 |
| 2023 | 2 |
| 2024 | 6 |
| 2025 | 5 |
| 2026 | 1 |