Skip to content

Data collected

CVEs Live

D-Link vulnerabilities exploited in the wild

The D-Link CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

26
flaws with confirmed attacks
2
used by ransomware
1.5%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2025-29635Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DIR-823X

    D-Link DIR-823X Command Injection Vulnerability

    Severity

    7.2HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    87.9%99.8th pct

    KEV dates

    added due
  2. CVE-2022-37055Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · Routers

    D-Link Routers Buffer Overflow Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    55.5%99.0th pct

    KEV dates

    added due
  3. CVE-2020-25078Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DCS-2530L and DCS-2670L Devices

    D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    97.5%99.9th pct

    KEV dates

    added due
  4. CVE-2020-25079Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DCS-2530L and DCS-2670L Devices

    D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    54.0%99th pct

    KEV dates

    added due
  5. CVE-2022-40799Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DNR-322L

    D-Link DNR-322L Download of Code Without Integrity Check Vulnerability

    Severity

    8.8HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    33.7%98th pct

    KEV dates

    added due
  6. CVE-2024-0769Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DIR-859 Router

    D-Link DIR-859 Router Path Traversal Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    82.7%99.7th pct

    KEV dates

    added due
  7. CVE-2023-25280Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DIR-820 Router

    D-Link DIR-820 Router OS Command Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    97.9%99.9th pct

    KEV dates

    added due
  8. CVE-2021-40655Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DIR-605 Router

    D-Link DIR-605 Router Information Disclosure Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    86.7%99.7th pct

    KEV dates

    added due
  9. CVE-2014-100005Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DIR-600 Router

    D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability

    Severity

    8.0HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    43.5%99th pct

    KEV dates

    added due
  10. CVE-2024-3273Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · Multiple NAS Devices

    D-Link Multiple NAS Devices Command Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    99.997%100th pct

    KEV dates

    added due
  11. CVE-2024-3272Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · Multiple NAS Devices

    D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    98.0%99.9th pct

    KEV dates

    added due
  12. CVE-2016-20017Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    D-Link · DSL-2750B Devices

    D-Link DSL-2750B Devices Command Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · NVD

    Attack probability (EPSS)

    64.2%99.2th pct

    KEV dates

    added due

D-Link products in the catalog

Among the most recent entries, the products that appear most often are:

  • DCS-2530L and DCS-2670L Devices2 entries
  • Multiple NAS Devices2 entries
  • DIR-823X1 entry
  • Routers1 entry
  • DNR-322L1 entry
  • DIR-859 Router1 entry
  • DIR-820 Router1 entry
  • DIR-605 Router1 entry

Product names are the ones CISA uses in the catalog. To check a specific D-Link CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: D-Link security announcements.

Other vendors

Questions

How many D-Link vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 26 D-Link vulnerabilities as of 3 Oct 2026. CISA marks 2 of them as known to be used in ransomware campaigns.

What is the most recent D-Link entry in KEV?

CVE-2025-29635 (D-Link DIR-823X Command Injection Vulnerability), added on 24 Apr 2026 with a due date of 8 May 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every D-Link CVE?

No. It lists only the D-Link CVEs that CISA has confirmed as exploited. D-Link publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should D-Link vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections