How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to D-Link (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited D-Link vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2025-29635 | DIR-823X | D-Link DIR-823X Command Injection Vulnerability | 2026-04-24 | |
| CVE-2022-37055 | Routers | D-Link Routers Buffer Overflow Vulnerability | 2025-12-08 | |
| CVE-2020-25078 | DCS-2530L and DCS-2670L Devices | D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability | 2025-08-05 | |
| CVE-2020-25079 | DCS-2530L and DCS-2670L Devices | D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability | 2025-08-05 | |
| CVE-2022-40799 | DNR-322L | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability | 2025-08-05 | |
| CVE-2024-0769 | DIR-859 Router | D-Link DIR-859 Router Path Traversal Vulnerability | 2025-06-25 | |
| CVE-2023-25280 | DIR-820 Router | D-Link DIR-820 Router OS Command Injection Vulnerability | 2024-09-30 | |
| CVE-2021-40655 | DIR-605 Router | D-Link DIR-605 Router Information Disclosure Vulnerability | 2024-05-16 | |
| CVE-2014-100005 | DIR-600 Router | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability | 2024-05-16 | |
| CVE-2024-3273 | Multiple NAS Devices | D-Link Multiple NAS Devices Command Injection Vulnerability | 2024-04-11 | |
| CVE-2024-3272 | Multiple NAS Devices | D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability | 2024-04-11 | |
| CVE-2016-20017 | DSL-2750B Devices | D-Link DSL-2750B Devices Command Injection Vulnerability | 2024-01-08 | |
| CVE-2019-17621 | DIR-859 Router | D-Link DIR-859 Router Command Execution Vulnerability | 2023-06-29 | |
| CVE-2019-20500 | DWL-2600AP Access Point | D-Link DWL-2600AP Access Point Command Injection Vulnerability | 2023-06-29 | |
| CVE-2022-26258 | DIR-820L | D-Link DIR-820L Remote Code Execution Vulnerability | 2022-09-08 | |
| CVE-2018-6530 | Multiple Routers | D-Link Multiple Routers OS Command Injection Vulnerability | 2022-09-08 | ransomware |
| CVE-2011-4723 | DIR-300 Router | D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability | 2022-09-08 | |
| CVE-2019-16057 | DNS-320 Storage Device | D-Link DNS-320 Remote Code Execution Vulnerability | 2022-04-15 | ransomware |
| CVE-2021-45382 | Multiple Routers | D-Link Multiple Routers Remote Code Execution Vulnerability | 2022-04-04 | |
| CVE-2020-9377 | DIR-610 Devices | D-Link DIR-610 Devices Remote Command Execution | 2022-03-25 | |
| CVE-2019-16920 | Multiple Routers | D-Link Multiple Routers Command Injection Vulnerability | 2022-03-25 | |
| CVE-2016-11021 | DCS-930L Devices | D-Link DCS-930L Devices OS Command Injection Vulnerability | 2022-03-25 | |
| CVE-2013-5223 | DSL-2760U | D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability | 2022-03-25 | |
| CVE-2015-2051 | DIR-645 Router | D-Link DIR-645 Router Remote Code Execution Vulnerability | 2022-02-10 | |
| CVE-2020-29557 | DIR-825 R1 Devices | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability | 2021-11-03 | |
| CVE-2020-25506 | DNS-320 Device | D-Link DNS-320 Device Command Injection Vulnerability | 2021-11-03 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.