Dlink
5,318 known vulnerabilities
Top Products
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead
An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web inter
D-Link DCS-5220 devices have a buffer overflow. NOTE: This vulnerability only affects products that are no longer suppor
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch applicatio
An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass au
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_c
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication f
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attac
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured F
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interfa
An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could al
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metachara
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header.
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows u
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. The unauthenticate
D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-86
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-84
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1
An authentication-bypass issue was discovered on D-Link DAP-1522 devices 1.4x before 1.10b04Beta02. There exist a few pa
An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no outp
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration func
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled b
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a user performs a login a
D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary comma
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability onl
D-Link DIR-610 devices allow Information Disclosure via SERVICES=DEVICE.ACCOUNT%0AAUTHORIZED_GROUP=1 to getcfg.php. NOTE
D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart
D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search p
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription r
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.
D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Storage of Sensitive Information.
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.
D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstra
An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without autho
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modul
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The function do_cgi(), which processes cgi requests sup
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote
D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a suppo
Frequently Asked Questions
How many CVEs affect Dlink?
Dlink has 5,318 CVE records in our database, including 1320 critical and 2536 high severity vulnerabilities. 23 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Dlink vulnerabilities?
Dlink has 1320 critical severity (CVSS 9.0+) and 2536 high severity (CVSS 7.0-8.9) vulnerabilities. 23 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Dlink vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Dlink products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Dlink Vulnerabilities
CyberStrike scans your infrastructure for Dlink vulnerabilities and provides real-time remediation guidance.
Get Started