D-Link known exploited vulnerabilities
CISA lists 26 D-Link CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-04-24), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-3273 (Multiple NAS Devices): EPSS 100.0%, added 2024-04-11
- CVE-2019-16920 (Multiple Routers): EPSS 100.0%, added 2022-03-25
- CVE-2020-25506 (DNS-320 Device): EPSS 100.0%, added 2021-11-03
- CVE-2024-3272 (Multiple NAS Devices): EPSS 98.0%, added 2024-04-11
- CVE-2023-25280 (DIR-820 Router): EPSS 97.9%, added 2024-09-30
Most affected D-Link products
Multiple Routers (3), DCS-2530L and DCS-2670L Devices (2), DIR-859 Router (2), Multiple NAS Devices (2), DIR-823X (1), Routers (1), DNR-322L (1), DIR-820 Router (1), DIR-605 Router (1), DIR-600 Router (1), DSL-2750B Devices (1), DWL-2600AP Access Point (1).
All D-Link CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-29635 | DIR-823X | DIR-823X Command Injection | 2026-04-24 | 2026-05-08 | 87.9% | – |
| CVE-2022-37055 | Routers | Routers Buffer Overflow | 2025-12-08 | 2025-12-29 | 55.5% | – |
| CVE-2022-40799 | DNR-322L | DNR-322L Download of Code Without Integrity Check | 2025-08-05 | 2025-08-26 | 33.7% | – |
| CVE-2020-25079 | DCS-2530L and DCS-2670L Devices | DCS-2530L and DCS-2670L Command Injection | 2025-08-05 | 2025-08-26 | 54.0% | – |
| CVE-2020-25078 | DCS-2530L and DCS-2670L Devices | DCS-2530L and DCS-2670L Devices Unspecified | 2025-08-05 | 2025-08-26 | 97.5% | – |
| CVE-2024-0769 | DIR-859 Router | DIR-859 Router Path Traversal | 2025-06-25 | 2025-07-16 | 82.7% | – |
| CVE-2023-25280 | DIR-820 Router | DIR-820 Router OS Command Injection | 2024-09-30 | 2024-10-21 | 97.9% | – |
| CVE-2021-40655 | DIR-605 Router | DIR-605 Router Information Disclosure | 2024-05-16 | 2024-06-06 | 86.7% | – |
| CVE-2014-100005 | DIR-600 Router | DIR-600 Router Cross-Site Request Forgery (CSRF) | 2024-05-16 | 2024-06-06 | 43.5% | – |
| CVE-2024-3273 | Multiple NAS Devices | Multiple NAS Devices Command Injection | 2024-04-11 | 2024-05-02 | 100.0% | – |
| CVE-2024-3272 | Multiple NAS Devices | Multiple NAS Devices Use of Hard-Coded Credentials | 2024-04-11 | 2024-05-02 | 98.0% | – |
| CVE-2016-20017 | DSL-2750B Devices | DSL-2750B Devices Command Injection | 2024-01-08 | 2024-01-29 | 64.2% | – |
| CVE-2019-20500 | DWL-2600AP Access Point | DWL-2600AP Access Point Command Injection | 2023-06-29 | 2023-07-20 | 97.1% | – |
| CVE-2019-17621 | DIR-859 Router | DIR-859 Router Command Execution | 2023-06-29 | 2023-07-20 | 89.6% | – |
| CVE-2022-26258 | DIR-820L | DIR-820L Remote Code Execution | 2022-09-08 | 2022-09-29 | 92.0% | – |
| CVE-2018-6530 | Multiple Routers | Multiple Routers OS Command Injection | 2022-09-08 | 2022-09-29 | 96.7% | Yes |
| CVE-2011-4723 | DIR-300 Router | DIR-300 Router Cleartext Storage of a Password | 2022-09-08 | 2022-09-29 | 3.1% | – |
| CVE-2019-16057 | DNS-320 Storage Device | DNS-320 Remote Code Execution | 2022-04-15 | 2022-05-06 | 86.5% | Yes |
| CVE-2021-45382 | Multiple Routers | Multiple Routers Remote Code Execution | 2022-04-04 | 2022-04-25 | 97.8% | – |
| CVE-2020-9377 | DIR-610 Devices | DIR-610 Devices Remote Command Execution | 2022-03-25 | 2022-04-15 | 21.3% | – |
| CVE-2019-16920 | Multiple Routers | Multiple Routers Command Injection | 2022-03-25 | 2022-04-15 | 100.0% | – |
| CVE-2016-11021 | DCS-930L Devices | DCS-930L Devices OS Command Injection | 2022-03-25 | 2022-04-15 | 68.9% | – |
| CVE-2013-5223 | DSL-2760U | DSL-2760U Gateway Cross-Site Scripting | 2022-03-25 | 2022-04-15 | 50.8% | – |
| CVE-2015-2051 | DIR-645 Router | DIR-645 Router Remote Code Execution | 2022-02-10 | 2022-08-10 | 97.1% | – |
| CVE-2020-29557 | DIR-825 R1 Devices | DIR-825 R1 Devices Buffer Overflow | 2021-11-03 | 2022-05-03 | 54.3% | – |
| CVE-2020-25506 | DNS-320 Device | DNS-320 Device Command Injection | 2021-11-03 | 2022-05-03 | 100.0% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors