Brand
D-Link: actively exploited vulnerabilities
27 vulnerabilities in D-Link products (Routers (DIR, DWR, DSR), NAS DNS (ShareCenter), DCS cameras…) are in CISA’s catalog of exploited vulnerabilities. Last added: April 24, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
27 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one D-Link category to your radar, or open its page.
- Home and small-office routers, cameras and IoT 23 vulnerabilities
- Backup, storage and NAS 4 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single D-Link product (Routers (DIR, DWR, DSR), NAS DNS (ShareCenter)…) rather than the whole brand.
- Routers (DIR, DWR, DSR)15 vulnerabilities, Home routers and IoT
- NAS DNS (ShareCenter)4 vulnerabilities, Backup and NAS
- DCS cameras3 vulnerabilities, Home routers and IoT
- DSL modem-routers2 vulnerabilities, Home routers and IoT
- DNR video recorders (NVR)1 vulnerability, Home routers and IoT
- Access points (DAP, DWL)1 vulnerability, Home routers and IoT
- D-Link and TRENDnet routers1 vulnerability, Home routers and IoT
Names used by CISA: D-Link, D-Link and TRENDnet. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 0 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 1 |
| Jan 7, 2026 to Feb 5, 2026 | 0 |
| Feb 6, 2026 to Mar 7, 2026 | 0 |
| Mar 8, 2026 to Apr 6, 2026 | 0 |
| Apr 7, 2026 to May 6, 2026 | 1 |
| May 7, 2026 to Jun 5, 2026 | 0 |
| Jun 6, 2026 to Jul 5, 2026 | 0 |
| Jul 6, 2026 to Aug 4, 2026 | 0 |
| Aug 5, 2026 to Sep 3, 2026 | 0 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this D-Link list.
- Rank 1
D-Link Routers (DIR, DWR, DSR)CVE-2022-37055
D-Link Routers Buffer Overflow Vulnerability
CVE from 2022, added in 2025
CVSS severity 9.8critical
Added Dec 8, 2025
- Rank 2
D-Link Routers (DIR, DWR, DSR)CVE-2025-29635
D-Link DIR-823X Command Injection Vulnerability
CVSS severity 7.2high
Added Apr 24, 2026
- Rank 3
D-Link Routers (DIR, DWR, DSR)CVE-2024-0769
D-Link DIR-859 Router Path Traversal Vulnerability
CVSS severity 9.8critical
Added Jun 25, 2025
- Rank 4
D-Link DSL modem-routersCVE-2016-20017
D-Link DSL-2750B Devices Command Injection Vulnerability
CVE from 2016, added in 2024
CVSS severity 9.8critical
Added Jan 8, 2024
- Rank 5
D-Link Routers (DIR, DWR, DSR)CVE-2019-17621
D-Link DIR-859 Router Command Execution Vulnerability
CVE from 2019, added in 2023
CVSS severity 9.8critical
Added Jun 29, 2023
- Rank 6
D-Link Routers (DIR, DWR, DSR)CVE-2018-6530
D-Link Multiple Routers OS Command Injection Vulnerability
RansomwareCVE from 2018, added in 2022
CVSS severity 9.8critical
Added Sep 8, 2022
- Rank 7
D-Link NAS DNS (ShareCenter)CVE-2020-25506
D-Link DNS-320 Device Command Injection Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 8
D-Link Routers (DIR, DWR, DSR)CVE-2020-29557
D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 9
D-Link DCS camerasCVE-2020-25079
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
CVE from 2020, added in 2025
CVSS severity 8.8high
Added Aug 5, 2025
- Rank 10
D-Link DNR video recorders (NVR)CVE-2022-40799
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
CVE from 2022, added in 2025
CVSS severity 8.8high
Added Aug 5, 2025
Show 3 more vulnerabilities
- Rank 11
D-Link Access points (DAP, DWL)CVE-2019-20500
D-Link DWL-2600AP Access Point Command Injection Vulnerability
CVE from 2019, added in 2023
CVSS severity 7.8high
Added Jun 29, 2023
- Rank 12
D-Link DCS camerasCVE-2020-25078
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
CVE from 2020, added in 2025
CVSS severity 7.5high
Added Aug 5, 2025
- Rank 13
D-Link DSL modem-routersCVE-2013-5223
D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
CVE from 2013, added in 2022
CVSS severity 5.4medium
Added Mar 25, 2022
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
D-Link Routers (DIR, DWR, DSR)CVE-2023-25280
D-Link DIR-820 Router OS Command Injection Vulnerability
End of life
CVSS severity 9.8critical
Added Sep 30, 2024
D-Link Routers (DIR, DWR, DSR)CVE-2014-100005
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
End of lifeCVE from 2014, added in 2024
CVSS severity 8.0high
Added May 16, 2024
D-Link Routers (DIR, DWR, DSR)CVE-2021-40655
D-Link DIR-605 Router Information Disclosure Vulnerability
End of lifeCVE from 2021, added in 2024
CVSS severity 7.5high
Added May 16, 2024
D-Link NAS DNS (ShareCenter)CVE-2024-3272
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
End of life
CVSS severity 9.8critical
Added Apr 11, 2024
D-Link NAS DNS (ShareCenter)CVE-2024-3273
D-Link Multiple NAS Devices Command Injection Vulnerability
End of life
CVSS severity 9.8critical
Added Apr 11, 2024
D-Link Routers (DIR, DWR, DSR)CVE-2011-4723
D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability
End of lifeCVE from 2011, added in 2022
CVSS severity 5.7medium
Added Sep 8, 2022
D-Link Routers (DIR, DWR, DSR)CVE-2022-26258
D-Link DIR-820L Remote Code Execution Vulnerability
End of life
CVSS severity 9.8critical
Added Sep 8, 2022
D-Link NAS DNS (ShareCenter)CVE-2019-16057
D-Link DNS-320 Remote Code Execution Vulnerability
RansomwareEnd of lifeCVE from 2019, added in 2022
CVSS severity 9.8critical
Added Apr 15, 2022
D-Link Routers (DIR, DWR, DSR)CVE-2021-45382
D-Link Multiple Routers Remote Code Execution Vulnerability
End of life
CVSS severity 9.8critical
Added Apr 4, 2022
D-Link and TRENDnet routersCVE-2015-1187
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
End of lifeCVE from 2015, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
Show 4 more vulnerabilities
D-Link DCS camerasCVE-2016-11021
D-Link DCS-930L Devices OS Command Injection Vulnerability
End of lifeCVE from 2016, added in 2022
CVSS severity 7.2high
Added Mar 25, 2022
D-Link Routers (DIR, DWR, DSR)CVE-2019-16920
D-Link Multiple Routers Command Injection Vulnerability
End of lifeCVE from 2019, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
D-Link Routers (DIR, DWR, DSR)CVE-2020-9377
D-Link DIR-610 Devices Remote Command Execution
End of lifeCVE from 2020, added in 2022
CVSS severity 8.8high
Added Mar 25, 2022
D-Link Routers (DIR, DWR, DSR)CVE-2015-2051
D-Link DIR-645 Router Remote Code Execution Vulnerability
End of lifeCVE from 2015, added in 2022
CVSS severity 8.8high
Added Feb 10, 2022
Follow and verify
Get new D-Link vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.