Vendor
D-Link vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 109 vulnerabilities in D-Link: 7 in the last 7 days and 54 in the last 90 days, 62 of them critical and 25 exploited in the wild. The most recent, CVE-2025-51457, was published on 25 September 2026. 19 technologies have a page of their own.
- Last 7 days
- 7
- Last 90 days
- 54
- Critical, all time
- 62
- Exploited in the wild
- 25
About D-Link
D-Link is a global leader in designing and developing networking and connectivity products for consumers, small businesses, medium to large-sized enterprises, and service providers.
D-Link technologies
- D-Link DWR-M96115
- D-Link DNS-340L7
- D-Link DIR-823G5
- D-Link DNS-320L5
- D-Link DWR-M9215
- D-Link DNR-202L4
- D-Link DNR-322L4
- D-Link DNS-1204
- D-Link DNS-315L4
- D-Link DNS-3454
- D-Link DWR-M9204
- D-Link DCS-935L3
- D-Link DI-84003
- D-Link DIR-8163
- D-Link DIR-825M3
- D-Link DNS-320 ShareCenter NAS3
- D-Link DNS-320LW3
- D-Link DNS-3213
- D-Link DNS-327L3
Latest D-Link vulnerabilities
- CVE-2025-51457: D-Link DAP-2610 authenticated command injection in web interfacehighCVSS 8.8
- CVE-2026-96891: D-Link DIR-825 out-of-bounds write in L2TP hostname parsingcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-95675: D-Link DAP-1360 unauthenticated remote code execution in web interfacecriticalCVSS 9.8EPSS 2.1%
- CVE-2026-94089: D-Link DIR-868L stack-based buffer overflow in authentication handlercriticalCVSS 10EPSS 1.0%
- CVE-2026-94050: D-Link DIR-X1860Z information disclosure in ubus JSON-RPCmediumCVSS 4.3EPSS 0.4%
- CVE-2026-94036: D-Link DIR-X1860Z improper access control in ubus management interfacehighCVSS 8.8EPSS 0.6%
- CVE-2026-93958: D-Link R95 BE9500 command injection in DHMAPIcriticalCVSS 9.1EPSS 2.7%
- CVE-2026-91001: D-Link DI-8400 stack buffer overflow in DDNS configurationcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-90881: D-Link DIR-882 information disclosure in CGI binarymediumCVSS 5.3EPSS 0.8%
- CVE-2026-90880: D-Link DSL-3782 command injection in DiagnosticshighCVSS 7.4EPSS 1.9%
- CVE-2026-90706: D-Link DWR-M921 OS command injection in formWscmediumCVSS 6.6EPSS 2.3%
- CVE-2026-90705: D-Link DWR-M921 OS command injection in formSysCmdmediumCVSS 6.6EPSS 2.3%
- CVE-2026-90704: D-Link DWR-M921 command injection in disk partition handlermediumCVSS 6.6EPSS 2.3%
- CVE-2026-90703: D-Link DWR-M921 OS command injection in formDiskCreateSharecriticalCVSS 9.1EPSS 3.6%
- CVE-2026-90702: D-Link DWR-M921 OS command injection in /boafrm/formDiskFormatcriticalCVSS 9.1EPSS 3.6%
- CVE-2026-90699: D-Link DWR-M920 OS command injection in formPinManageSetupcriticalCVSS 9.9EPSS 3.3%
- CVE-2026-90680: D-Link DIR-823G stack buffer overflow in SetStaticRouteSettingscriticalCVSS 9.9EPSS 0.9%
- CVE-2026-86510: D-Link DIR-822A out-of-bounds write in L2TP control message parsercriticalCVSS 9.9EPSS 0.5%
- CVE-2026-86509: D-Link DIR-895L stack-based buffer overflow in udhcpcdcriticalCVSS 9.6EPSS 0.7%
- CVE-2026-86297: D-Link DIR-605 off-by-one in L2TP tunnel handlerhighCVSS 8.1EPSS 1.1%
- CVE-2026-86296: D-Link DIR-822A stack-based buffer overflow in udhcpcdcriticalCVSS 10EPSS 1.4%
- CVE-2026-86295: D-Link DIR-895L command injection in udhcpcd sendACKhighCVSS 8.3EPSS 2.3%
- CVE-2026-85224: D-Link DNS-320 ShareCenter OS command injection in file_sharing.cgicriticalCVSS 9.1EPSS 3.6%
- CVE-2026-85223: D-Link DNS-340L OS command injection in dropbox.cgicriticalCVSS 9.9EPSS 3.3%
- CVE-2026-85222: D-Link DNS-340L OS command injection in addon_center.cgicriticalCVSS 9.1EPSS 3.6%
Most severe D-Link vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2015-2051: D-Link DIR-645 Router Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2021-32030: ASUS Routers authentication bypass in administrator interfacecriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2024-7399: Samsung MagicINFO 9 Server path traversalcriticalexploited in the wildCVSS 9.8EPSS 84.4%
- CVE-2022-37055: D-Link GO-RT-AC750 buffer overflow in cgibin and hnap_maincriticalexploited in the wildCVSS 9.8EPSS 80.5%
- CVE-2024-0769: D-Link DIR-859 path traversal in hedwig.cgicriticalexploited in the wildCVSS 9.8EPSS 75.2%
- CVE-2023-25280: D-Link DIR-820 Router OS Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-3273: D-Link Multiple NAS Devices Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-3272: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2016-20017: D-Link DSL-2750B Devices Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2019-17621: D-Link DIR-859 Router Command Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 15 | 15 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 2 | 1 | |
| 31 Aug 2026 | 11 | 9 | |
| 7 Sep 2026 | 5 | 3 | |
| 14 Sep 2026 | 14 | 7 | |
| 21 Sep 2026 | 3 | 2 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/d-link.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "D-Link vulnerabilities", https://junglewise.ai/threats/vendors/d-link, 26 September 2026.