Skip to content
English

Products › Brands

Brand

D-Link: actively exploited vulnerabilities

27 vulnerabilities in D-Link products (Routers (DIR, DWR, DSR), NAS DNS (ShareCenter), DCS cameras…) are in CISA’s catalog of exploited vulnerabilities. Last added: April 24, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

Add just one D-Link category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

  • Routers (DIR, DWR, DSR) 15 vulnerabilities · Home routers and IoT
  • NAS DNS (ShareCenter) 4 vulnerabilities · Backup and NAS
  • DCS cameras 3 vulnerabilities · Home routers and IoT
  • DSL modem-routers 2 vulnerabilities · Home routers and IoT
  • DNR video recorders (NVR) 1 vulnerability · Home routers and IoT
  • Access points (DAP, DWL) 1 vulnerability · Home routers and IoT
  • D-Link and TRENDnet routers 1 vulnerability · Home routers and IoT

Names used by CISA: D-Link, D-Link and TRENDnet. Product families: indicative classification by this site.

Pace of additions

Number of D-Link vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20261
Jan 2, 2026 to Jan 31, 20260
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20260
Apr 2, 2026 to May 1, 20261
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this D-Link list.

  1. Rank 1D-Link Routers (DIR, DWR, DSR)

    CVE-2022-37055

    CVE from 2022, added in 2025

    D-Link Routers Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 2D-Link Routers (DIR, DWR, DSR)

    CVE-2025-29635

    D-Link DIR-823X Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  3. Rank 3D-Link Routers (DIR, DWR, DSR)

    CVE-2024-0769

    D-Link DIR-859 Router Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 4D-Link DSL modem-routers

    CVE-2016-20017

    CVE from 2016, added in 2024

    D-Link DSL-2750B Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 5D-Link Routers (DIR, DWR, DSR)

    CVE-2019-17621

    CVE from 2019, added in 2023

    D-Link DIR-859 Router Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 6D-Link Routers (DIR, DWR, DSR)

    CVE-2018-6530

    RansomwareCVE from 2018, added in 2022

    D-Link Multiple Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7D-Link NAS DNS (ShareCenter)

    CVE-2020-25506

    D-Link DNS-320 Device Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  8. Rank 8D-Link Routers (DIR, DWR, DSR)

    CVE-2020-29557

    D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  9. Rank 9D-Link DCS cameras

    CVE-2020-25079

    CVE from 2020, added in 2025

    D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  10. Rank 10D-Link DNR video recorders (NVR)

    CVE-2022-40799

    CVE from 2022, added in 2025

    D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
Show 3 more vulnerabilities
  1. Rank 11D-Link Access points (DAP, DWL)

    CVE-2019-20500

    CVE from 2019, added in 2023

    D-Link DWL-2600AP Access Point Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  2. Rank 12D-Link DCS cameras

    CVE-2020-25078

    CVE from 2020, added in 2025

    D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  3. Rank 13D-Link DSL modem-routers

    CVE-2013-5223

    CVE from 2013, added in 2022

    D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. D-Link Routers (DIR, DWR, DSR)

    CVE-2023-25280

    End of life

    D-Link DIR-820 Router OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. D-Link Routers (DIR, DWR, DSR)

    CVE-2014-100005

    End of lifeCVE from 2014, added in 2024

    D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  3. D-Link Routers (DIR, DWR, DSR)

    CVE-2021-40655

    End of lifeCVE from 2021, added in 2024

    D-Link DIR-605 Router Information Disclosure Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  4. D-Link NAS DNS (ShareCenter)

    CVE-2024-3272

    End of life

    D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. D-Link NAS DNS (ShareCenter)

    CVE-2024-3273

    End of life

    D-Link Multiple NAS Devices Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 11, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. D-Link Routers (DIR, DWR, DSR)

    CVE-2011-4723

    End of lifeCVE from 2011, added in 2022

    D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    5.7 (medium)
  7. D-Link Routers (DIR, DWR, DSR)

    CVE-2022-26258

    End of life

    D-Link DIR-820L Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. D-Link NAS DNS (ShareCenter)

    CVE-2019-16057

    RansomwareEnd of lifeCVE from 2019, added in 2022

    D-Link DNS-320 Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. D-Link Routers (DIR, DWR, DSR)

    CVE-2021-45382

    End of life

    D-Link Multiple Routers Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 4, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. D-Link and TRENDnet routers

    CVE-2015-1187

    End of lifeCVE from 2015, added in 2022

    D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 4 more vulnerabilities
  1. D-Link DCS cameras

    CVE-2016-11021

    End of lifeCVE from 2016, added in 2022

    D-Link DCS-930L Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  2. D-Link Routers (DIR, DWR, DSR)

    CVE-2019-16920

    End of lifeCVE from 2019, added in 2022

    D-Link Multiple Routers Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. D-Link Routers (DIR, DWR, DSR)

    CVE-2020-9377

    End of lifeCVE from 2020, added in 2022

    D-Link DIR-610 Devices Remote Command Execution

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. D-Link Routers (DIR, DWR, DSR)

    CVE-2015-2051

    End of lifeCVE from 2015, added in 2022

    D-Link DIR-645 Router Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)

Follow and verify

Get new D-Link vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.