Brand
D-Link: actively exploited vulnerabilities
27 vulnerabilities in D-Link products (Routers (DIR, DWR, DSR), NAS DNS (ShareCenter), DCS cameras…) are in CISA’s catalog of exploited vulnerabilities. Last added: April 24, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
2 vulnerabilities added in the last 12 months
-
27 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one D-Link category to your radar, or open its page.
- Home and small-office routers, cameras and IoT 23 vulnerabilities
- Backup, storage and NAS 4 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Routers (DIR, DWR, DSR) 15 vulnerabilities · Home routers and IoT
- NAS DNS (ShareCenter) 4 vulnerabilities · Backup and NAS
- DCS cameras 3 vulnerabilities · Home routers and IoT
- DSL modem-routers 2 vulnerabilities · Home routers and IoT
- DNR video recorders (NVR) 1 vulnerability · Home routers and IoT
- Access points (DAP, DWL) 1 vulnerability · Home routers and IoT
- D-Link and TRENDnet routers 1 vulnerability · Home routers and IoT
Names used by CISA: D-Link, D-Link and TRENDnet. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 1 |
| Jan 2, 2026 to Jan 31, 2026 | 0 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 0 |
| Apr 2, 2026 to May 1, 2026 | 1 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 0 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 0 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this D-Link list.
Rank 1D-Link Routers (DIR, DWR, DSR)
CVE-2022-37055CVE from 2022, added in 2025
D-Link Routers Buffer Overflow Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 8, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 2D-Link Routers (DIR, DWR, DSR)
CVE-2025-29635D-Link DIR-823X Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 24, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.2 (high)
Rank 3D-Link Routers (DIR, DWR, DSR)
CVE-2024-0769D-Link DIR-859 Router Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 25, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 4D-Link DSL modem-routers
CVE-2016-20017CVE from 2016, added in 2024
D-Link DSL-2750B Devices Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 5D-Link Routers (DIR, DWR, DSR)
CVE-2019-17621CVE from 2019, added in 2023
D-Link DIR-859 Router Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6D-Link Routers (DIR, DWR, DSR)
CVE-2018-6530RansomwareCVE from 2018, added in 2022
D-Link Multiple Routers OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7D-Link NAS DNS (ShareCenter)
CVE-2020-25506D-Link DNS-320 Device Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 8D-Link Routers (DIR, DWR, DSR)
CVE-2020-29557D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 9D-Link DCS cameras
CVE-2020-25079CVE from 2020, added in 2025
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 5, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 10D-Link DNR video recorders (NVR)
CVE-2022-40799CVE from 2022, added in 2025
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 5, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Show 3 more vulnerabilities
Rank 11D-Link Access points (DAP, DWL)
CVE-2019-20500CVE from 2019, added in 2023
D-Link DWL-2600AP Access Point Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 29, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 12D-Link DCS cameras
CVE-2020-25078CVE from 2020, added in 2025
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 5, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 13D-Link DSL modem-routers
CVE-2013-5223CVE from 2013, added in 2022
D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.4 (medium)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
D-Link Routers (DIR, DWR, DSR)
CVE-2023-25280End of life
D-Link DIR-820 Router OS Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 30, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link Routers (DIR, DWR, DSR)
CVE-2014-100005End of lifeCVE from 2014, added in 2024
D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.0 (high)
D-Link Routers (DIR, DWR, DSR)
CVE-2021-40655End of lifeCVE from 2021, added in 2024
D-Link DIR-605 Router Information Disclosure Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- May 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
D-Link NAS DNS (ShareCenter)
CVE-2024-3272End of life
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 11, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link NAS DNS (ShareCenter)
CVE-2024-3273End of life
D-Link Multiple NAS Devices Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 11, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link Routers (DIR, DWR, DSR)
CVE-2011-4723End of lifeCVE from 2011, added in 2022
D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 5.7 (medium)
D-Link Routers (DIR, DWR, DSR)
CVE-2022-26258End of life
D-Link DIR-820L Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 8, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link NAS DNS (ShareCenter)
CVE-2019-16057RansomwareEnd of lifeCVE from 2019, added in 2022
D-Link DNS-320 Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link Routers (DIR, DWR, DSR)
CVE-2021-45382End of life
D-Link Multiple Routers Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Apr 4, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link and TRENDnet routers
CVE-2015-1187End of lifeCVE from 2015, added in 2022
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 4 more vulnerabilities
D-Link DCS cameras
CVE-2016-11021End of lifeCVE from 2016, added in 2022
D-Link DCS-930L Devices OS Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
D-Link Routers (DIR, DWR, DSR)
CVE-2019-16920End of lifeCVE from 2019, added in 2022
D-Link Multiple Routers Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
D-Link Routers (DIR, DWR, DSR)
CVE-2020-9377End of lifeCVE from 2020, added in 2022
D-Link DIR-610 Devices Remote Command Execution
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
D-Link Routers (DIR, DWR, DSR)
CVE-2015-2051End of lifeCVE from 2015, added in 2022
D-Link DIR-645 Router Remote Code Execution Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Feb 10, 2022
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Follow and verify
Get new D-Link vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.