CyberMax
Home › Exploited CVEs

D-Link known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 26 D-Link CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-04-24), and 2 are known to be used in ransomware campaigns.

D-Link CVEs added to CISA KEV per year
2021: 2202122022: 102022102023: 2202322024: 6202462025: 5202552026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected D-Link products

Multiple Routers (3), DCS-2530L and DCS-2670L Devices (2), DIR-859 Router (2), Multiple NAS Devices (2), DIR-823X (1), Routers (1), DNR-322L (1), DIR-820 Router (1), DIR-605 Router (1), DIR-600 Router (1), DSL-2750B Devices (1), DWL-2600AP Access Point (1).

All D-Link CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-29635DIR-823XDIR-823X Command Injection2026-04-242026-05-0887.9%–
CVE-2022-37055RoutersRouters Buffer Overflow2025-12-082025-12-2955.5%–
CVE-2022-40799DNR-322LDNR-322L Download of Code Without Integrity Check2025-08-052025-08-2633.7%–
CVE-2020-25079DCS-2530L and DCS-2670L DevicesDCS-2530L and DCS-2670L Command Injection2025-08-052025-08-2654.0%–
CVE-2020-25078DCS-2530L and DCS-2670L DevicesDCS-2530L and DCS-2670L Devices Unspecified2025-08-052025-08-2697.5%–
CVE-2024-0769DIR-859 RouterDIR-859 Router Path Traversal2025-06-252025-07-1682.7%–
CVE-2023-25280DIR-820 RouterDIR-820 Router OS Command Injection2024-09-302024-10-2197.9%–
CVE-2021-40655DIR-605 RouterDIR-605 Router Information Disclosure2024-05-162024-06-0686.7%–
CVE-2014-100005DIR-600 RouterDIR-600 Router Cross-Site Request Forgery (CSRF)2024-05-162024-06-0643.5%–
CVE-2024-3273Multiple NAS DevicesMultiple NAS Devices Command Injection2024-04-112024-05-02100.0%–
CVE-2024-3272Multiple NAS DevicesMultiple NAS Devices Use of Hard-Coded Credentials2024-04-112024-05-0298.0%–
CVE-2016-20017DSL-2750B DevicesDSL-2750B Devices Command Injection2024-01-082024-01-2964.2%–
CVE-2019-20500DWL-2600AP Access PointDWL-2600AP Access Point Command Injection2023-06-292023-07-2097.1%–
CVE-2019-17621DIR-859 RouterDIR-859 Router Command Execution2023-06-292023-07-2089.6%–
CVE-2022-26258DIR-820LDIR-820L Remote Code Execution2022-09-082022-09-2992.0%–
CVE-2018-6530Multiple RoutersMultiple Routers OS Command Injection2022-09-082022-09-2996.7%Yes
CVE-2011-4723DIR-300 RouterDIR-300 Router Cleartext Storage of a Password2022-09-082022-09-293.1%–
CVE-2019-16057DNS-320 Storage DeviceDNS-320 Remote Code Execution2022-04-152022-05-0686.5%Yes
CVE-2021-45382Multiple RoutersMultiple Routers Remote Code Execution2022-04-042022-04-2597.8%–
CVE-2020-9377DIR-610 DevicesDIR-610 Devices Remote Command Execution2022-03-252022-04-1521.3%–
CVE-2019-16920Multiple RoutersMultiple Routers Command Injection2022-03-252022-04-15100.0%–
CVE-2016-11021DCS-930L DevicesDCS-930L Devices OS Command Injection2022-03-252022-04-1568.9%–
CVE-2013-5223DSL-2760UDSL-2760U Gateway Cross-Site Scripting2022-03-252022-04-1550.8%–
CVE-2015-2051DIR-645 RouterDIR-645 Router Remote Code Execution2022-02-102022-08-1097.1%–
CVE-2020-29557DIR-825 R1 DevicesDIR-825 R1 Devices Buffer Overflow2021-11-032022-05-0354.3%–
CVE-2020-25506DNS-320 DeviceDNS-320 Device Command Injection2021-11-032022-05-03100.0%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors