Skip to content
English

Products › Network and edge

Network and edge

Home and small-office routers, cameras and IoT

Small-office routers, home gateways, IP cameras, video recorders and connected devices: often forgotten and rarely updated.

For example: D-Link, TP-Link, NETGEAR, DrayTek, Hikvision.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1Hikvision IP cameras and recorders (NVR/DVR)

    CVE-2017-7921

    CVE from 2017, added in 2026

    Hikvision Multiple Products Improper Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 5, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 2D-Link Routers (DIR, DWR, DSR)

    CVE-2022-37055

    CVE from 2022, added in 2025

    D-Link Routers Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 8, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Digiever DS-2105 Pro

    CVE-2023-52163

    CVE from 2023, added in 2025

    Digiever DS-2105 Pro Missing Authorization Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 22, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. Rank 4Smartbedded Meteobridge

    CVE-2025-4008

    Smartbedded Meteobridge Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  5. Rank 5DD-WRT

    CVE-2021-27137

    Hunt for compromise (CISA)CVE from 2021, added in 2026

    DD-WRT Stack-Based Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 21, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  6. Rank 6D-Link Routers (DIR, DWR, DSR)

    CVE-2025-29635

    D-Link DIR-823X Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 24, 2026
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  7. Rank 7D-Link Routers (DIR, DWR, DSR)

    CVE-2024-0769

    D-Link DIR-859 Router Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8ASUS Routers (RT, GT, ZenWiFi)

    CVE-2021-32030

    CVE from 2021, added in 2025

    ASUS Routers Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9DrayTek Vigor (routers)

    CVE-2024-12987

    DrayTek Vigor Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 15, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10GeoVision Cameras and video servers

    CVE-2024-11120

    GeoVision Devices OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 64 more vulnerabilities
  1. Rank 11GeoVision Cameras and video servers

    CVE-2024-6047

    GeoVision Devices OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 7, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Edimax IC-7100 IP Camera

    CVE-2025-1316

    Edimax IC-7100 IP Camera OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 19, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13DrayTek Vigor (routers)

    CVE-2020-15415

    CVE from 2020, added in 2024

    DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Dahua IP Camera Firmware

    CVE-2021-33044

    CVE from 2021, added in 2024

    Dahua IP Camera Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Dahua IP Camera Firmware

    CVE-2021-33045

    CVE from 2021, added in 2024

    Dahua IP Camera Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 16D-Link DSL modem-routers

    CVE-2016-20017

    CVE from 2016, added in 2024

    D-Link DSL-2750B Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 17Realtek Router SDKs (Jungle, AP-Router)

    CVE-2014-8361

    CVE from 2014, added in 2023

    Realtek SDK Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 18Zyxel Home gateways and routers (DSL, CPE)

    CVE-2017-18368

    CVE from 2017, added in 2023

    Zyxel P660HN-T1A Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 7, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 19D-Link Routers (DIR, DWR, DSR)

    CVE-2019-17621

    CVE from 2019, added in 2023

    D-Link DIR-859 Router Command Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 20D-Link Routers (DIR, DWR, DSR)

    CVE-2018-6530

    RansomwareCVE from 2018, added in 2022

    D-Link Multiple Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  11. Rank 21NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-6862

    CVE from 2017, added in 2022

    NETGEAR Multiple Devices Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  12. Rank 22NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2016-10174

    CVE from 2016, added in 2022

    NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  13. Rank 23NETGEAR Wi-Fi access points (WAC, WNAP)

    CVE-2016-1555

    CVE from 2016, added in 2022

    NETGEAR Multiple WAP Devices Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  14. Rank 24Cisco RV routers (Small Business)

    CVE-2018-0125

    CVE from 2018, added in 2022

    Cisco VPN Routers Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-6077

    CVE from 2017, added in 2022

    NETGEAR DGN2200 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Cisco RV routers (Small Business)

    CVE-2022-20699

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Cisco RV routers (Small Business)

    CVE-2022-20700

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Hikvision IP cameras and recorders (NVR/DVR)

    CVE-2021-36260

    Hikvision Improper Input Validation

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Realtek Router SDKs (Jungle, AP-Router)

    CVE-2021-35394

    Realtek Jungle SDK Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Tenda Wi-Fi routers

    CVE-2018-14558

    CVE from 2018, added in 2021

    Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Sumavision Enhanced Multimedia Router (EMR)

    CVE-2020-10181

    Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Tenda Wi-Fi routers

    CVE-2020-10987

    Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  23. Rank 33D-Link Routers (DIR, DWR, DSR)

    CVE-2020-29557

    D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  24. Rank 34DrayTek Vigor (routers)

    CVE-2020-8515

    Multiple DrayTek Vigor Routers Web Management Page Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Arcadyan Buffalo Firmware

    CVE-2021-20090

    Arcadyan Buffalo Firmware Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Tenda Wi-Fi routers

    CVE-2021-31755

    Tenda AC11 Router Stack Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  27. Rank 37Realtek Router SDKs (Jungle, AP-Router)

    CVE-2021-35395

    Realtek AP-Router SDK Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  28. Rank 38PTZOptics PT30X-SDI/NDI Cameras

    CVE-2024-8956

    PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 4, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  29. Rank 39TP-Link Range extenders and access points (TL-WA, RE)

    CVE-2020-24363

    CVE from 2020, added in 2025

    TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  30. Rank 40D-Link DCS cameras

    CVE-2020-25079

    CVE from 2020, added in 2025

    D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  31. Rank 41D-Link DNR video recorders (NVR)

    CVE-2022-40799

    CVE from 2022, added in 2025

    D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  32. Rank 42TP-Link TL-WR (Wi-Fi routers)

    CVE-2023-33538

    CVE from 2023, added in 2025

    TP-Link Multiple Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 16, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  33. Rank 43ASUS Routers (RT, GT, ZenWiFi)

    CVE-2023-39780

    CVE from 2023, added in 2025

    ASUS RT-AX55 Routers OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 2, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  34. Rank 44Zyxel Home gateways and routers (DSL, CPE)

    CVE-2024-40890

    Zyxel DSL CPE OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  35. Rank 45Zyxel Home gateways and routers (DSL, CPE)

    CVE-2024-40891

    Zyxel DSL CPE OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  36. Rank 46QNAP VioStor NVR

    CVE-2023-47565

    QNAP VioStor NVR OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 21, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  37. Rank 47FXC AE1021, AE1021PE

    CVE-2023-49897

    FXC AE1021, AE1021PE OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 21, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  38. Rank 48Zyxel Home gateways and routers (DSL, CPE)

    CVE-2017-6884

    RansomwareCVE from 2017, added in 2023

    Zyxel EMG2926 Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  39. Rank 49TP-Link Archer (Wi-Fi routers)

    CVE-2023-1389

    TP-Link Archer AX-21 Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 1, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  40. Rank 50Cisco RV routers (Small Business)

    CVE-2019-15271

    CVE from 2019, added in 2022

    Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  41. Rank 51NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2016-6277

    CVE from 2016, added in 2022

    NETGEAR Multiple Routers Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    8.8 (high)
  42. Rank 52Amcrest Cameras and Network Video Recorder (NVR)

    CVE-2020-5735

    Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  43. Rank 53NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-5521

    CVE from 2017, added in 2022

    NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  44. Rank 54Cisco RV routers (Small Business)

    CVE-2022-20703

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  45. Rank 55Cisco RV routers (Small Business)

    CVE-2022-20708

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  46. Rank 56D-Link Access points (DAP, DWL)

    CVE-2019-20500

    CVE from 2019, added in 2023

    D-Link DWL-2600AP Access Point Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 29, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  47. Rank 57Cisco RV routers (Small Business)

    CVE-2022-20701

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  48. Rank 58D-Link DCS cameras

    CVE-2020-25078

    CVE from 2020, added in 2025

    D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  49. Rank 59DrayTek VigorConnect

    CVE-2021-20123

    CVE from 2021, added in 2024

    Draytek VigorConnect Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  50. Rank 60DrayTek VigorConnect

    CVE-2021-20124

    CVE from 2021, added in 2024

    Draytek VigorConnect Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  51. Rank 61TP-Link Archer (Wi-Fi routers)

    CVE-2015-3035

    CVE from 2015, added in 2022

    TP-Link Multiple Archer Devices Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  52. Rank 62Cisco RV routers (Small Business)

    CVE-2019-1653

    CVE from 2019, added in 2021

    Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  53. Rank 63Netis WF2419 Devices

    CVE-2019-19356

    CVE from 2019, added in 2021

    Netis WF2419 Devices Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  54. Rank 64TVT NVMS-1000

    CVE-2019-20085

    CVE from 2019, added in 2021

    TVT NVMS-1000 Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  55. Rank 65TP-Link Archer (Wi-Fi routers)

    CVE-2025-9377

    TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  56. Rank 66Cisco RV routers (Small Business)

    CVE-2023-20118

    CVE from 2023, added in 2025

    Cisco Small Business RV Series Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  57. Rank 67Reolink IP cameras

    CVE-2019-11001

    CVE from 2019, added in 2024

    Reolink Multiple IP Cameras OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  58. Rank 68Reolink IP cameras

    CVE-2021-40407

    CVE from 2021, added in 2024

    Reolink RLC-410W IP Camera OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  59. Rank 69PTZOptics PT30X-SDI/NDI Cameras

    CVE-2024-8957

    PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 4, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  60. Rank 70Plex Media Server

    CVE-2020-5741

    CVE from 2020, added in 2023

    Plex Media Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  61. Rank 71Cisco RV routers (Small Business)

    CVE-2019-1652

    CVE from 2019, added in 2022

    Cisco Small Business Routers Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  62. Rank 72Pi-hole AdminLTE

    CVE-2020-8816

    Pi-Hole AdminLTE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2021
    CISA deadline
    182 days
    CVSS severity
    7.2 (high)
  63. Rank 73TP-Link TL-WR (Wi-Fi routers)

    CVE-2023-50224

    CVE from 2023, added in 2025

    TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 3, 2025
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  64. Rank 74D-Link DSL modem-routers

    CVE-2013-5223

    CVE from 2013, added in 2022

    D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. NUUO NVRmini / NVRmini2

    CVE-2018-14933

    End of lifeCVE from 2018, added in 2024

    NUUO NVRmini Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. NUUO NVRmini / NVRmini2

    CVE-2022-23227

    End of lifeCVE from 2022, added in 2024

    NUUO NVRmini2 Devices Missing Authentication Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Dec 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. D-Link Routers (DIR, DWR, DSR)

    CVE-2023-25280

    End of life

    D-Link DIR-820 Router OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 30, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. D-Link Routers (DIR, DWR, DSR)

    CVE-2014-100005

    End of lifeCVE from 2014, added in 2024

    D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  5. D-Link Routers (DIR, DWR, DSR)

    CVE-2021-40655

    End of lifeCVE from 2021, added in 2024

    D-Link DIR-605 Router Information Disclosure Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  6. D-Link Routers (DIR, DWR, DSR)

    CVE-2011-4723

    End of lifeCVE from 2011, added in 2022

    D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    5.7 (medium)
  7. D-Link Routers (DIR, DWR, DSR)

    CVE-2022-26258

    End of life

    D-Link DIR-820L Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 8, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. D-Link Routers (DIR, DWR, DSR)

    CVE-2021-45382

    End of life

    D-Link Multiple Routers Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Apr 4, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. DASAN Zhone (DZS) Gigabit Passive Optical Network (GPON) Routers

    CVE-2018-10561

    End of lifeCVE from 2018, added in 2022

    Dasan GPON Routers Authentication Bypass Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. DASAN Zhone (DZS) Gigabit Passive Optical Network (GPON) Routers

    CVE-2018-10562

    RansomwareEnd of lifeCVE from 2018, added in 2022

    Dasan GPON Routers Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 6 more vulnerabilities
  1. D-Link and TRENDnet routers

    CVE-2015-1187

    End of lifeCVE from 2015, added in 2022

    D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. D-Link DCS cameras

    CVE-2016-11021

    End of lifeCVE from 2016, added in 2022

    D-Link DCS-930L Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  3. NETGEAR Routers (DGN, WNR, Nighthawk)

    CVE-2017-6334

    End of lifeCVE from 2017, added in 2022

    NETGEAR DGN2200 Devices OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  4. D-Link Routers (DIR, DWR, DSR)

    CVE-2019-16920

    End of lifeCVE from 2019, added in 2022

    D-Link Multiple Routers Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  5. D-Link Routers (DIR, DWR, DSR)

    CVE-2020-9377

    End of lifeCVE from 2020, added in 2022

    D-Link DIR-610 Devices Remote Command Execution

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  6. D-Link Routers (DIR, DWR, DSR)

    CVE-2015-2051

    End of lifeCVE from 2015, added in 2022

    D-Link DIR-645 Router Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.