ZeroHour

Vulnerabilities

91 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-29635
Authenticated Command Injection in D-Link DIR-823X Routers Exploited by Mirai Botnet

CVE-2025-29635 is a command injection flaw (CWE-77) in D-Link DIR-823X router firmware builds 240126 and 240802 that permits arbitrary command execution on the device. It is triggered by sending a crafted POST request to the /goform/set_prohibiting endpoint, and because the flaw requires high privileges (CVSS PR:H), the attacker must hold valid administrative credentials, which in botnet campaigns is typically achieved via default or weak passwords. Successful exploitation yields full remote command execution on the router, which in the observed campaign has been used by Mirai-variant botnets to enroll devices for DDoS activity. Any DIR-823X running the listed firmware builds is affected, with exposure concentrated in units whose web administration interface is reachable from the internet. The flaw was added to CISA's KEV catalog on 2026-04-24 after documented in-the-wild exploitation (an Akamai report on a Mirai campaign and a public PoC), and its EPSS score of 87.9% places it in the top percentile for near-term exploitation risk.

Do: Apply updated DIR-823X firmware per D-Link's guidance (a fixed build is not specified in this data) or the applicable BOD 22-01 mitigation deadline, reported as May 2026 for federal agencies. Until patched, ensure the router's admin interface is not exposed to the WAN and change default/weak credentials, since exploitation requires valid administrative access. Check devices for indicators of Mirai-style compromise (unexpected processes, outbound scanning or DDoS traffic) and review logs for POST requests to /goform/set_prohibiting from untrusted sources.

7.288% KEV PoC ×2
  • D-Link DIR-823X firmware 240126 and 240802 (the builds named in the advisory; no fixed version is specified in this data)
moderatelikely thousands of internet-exposed DIR-823X routers (roughly 1k-10k units directly attackable; installed base of the model could be higher)
CVE-2024-3273
+1 in the same advisory: …3272
Command Injection in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L NAS Devices

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L network-attached storage devices contain a command injection flaw (CWE-77) in which attacker-controlled input is passed to an underlying system shell. The flaw can be triggered remotely, and when chained with the related CVE-2024-3272 it allows an unauthenticated attacker to execute arbitrary commands on the device without credentials. Successful exploitation gives an attacker full control over the affected NAS, providing a foothold for data theft, malware deployment, or further network compromise. Users of these legacy D-Link NAS models are affected; all hardware revisions of these products have reached end-of-life or end-of-service, so no routine security updates are being delivered through the normal lifecycle. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, indicating exploitation in the wild, with a very high EPSS probability of near-term exploitation.

Do: Because these devices are EOL/EOS, retire and replace them per D-Link's lifecycle guidance rather than waiting for a patch; check vendor channels for any interim firmware releases. As an interim mitigation, disconnect these NAS devices from direct internet access or restrict access via firewall rules, and review device/web server logs for suspicious requests indicating command injection attempts.

9.8100% KEV PoC
  • D-Link DNS-320L NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • D-Link DNS-325 NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • D-Link DNS-327L NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • +1 more
largeon the order of tens of thousands of internet-exposed D-Link NAS devices (estimated, not confirmed by the supplied data)
CVE-2024-0769
Unauthenticated Path Traversal in D-Link DIR-859 Router (hedwig.cgi)

D-Link DIR-859 routers running firmware 1.06B01 contain a critical path traversal flaw (CWE-22, CVSS 9.8) in the HTTP POST request handler of /hedwig.cgi. An unauthenticated remote attacker can manipulate the 'service' parameter with a directory-traversal path (e.g., ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml) to access files outside the intended location. Given the critical rating with high confidentiality, integrity, and availability impacts, successful exploitation can expose sensitive router configuration (potentially including credentials) and lead to full device compromise. Only DIR-859 units still in service are affected: D-Link has confirmed the product is end-of-life, so no patched firmware is available. Exploitation is now in the wild — CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-06-25, EPSS puts 30-day exploitation probability at 82.7%, a public proof-of-concept exists, and news reports indicate threat actors are actively exploiting D-Link DIR-series flaws.

Do: Because the DIR-859 is end-of-life, there is no firmware fix — replace the router with a currently supported model, as the vendor recommends. If replacement is not immediate, minimize exposure by disabling remote/WAN management access to the device and any port-forwarding or UPnP rules that expose the web interface, and monitor for exploitation attempts against /hedwig.cgi. Federal agencies must follow CISA BOD 22-01 and remediate by the assigned KEV due date.

9.883% KEV PoC
  • D-Link DIR-859 Router (DIR-859 firmware) 1.06B01 (confirmed affected; product is end-of-life with no fixed release, so all in-service DIR-859 units should be treated as affected)
Unknown; plausibly tens of thousands of DIR-859 units remain deployed, with an internet-exposed subset likely in the thousands
CVE-2023-25280
Unauthenticated OS Command Injection in D-Link DIR-820 Router (CVE-2023-25280)

CVE-2023-25280 is an unauthenticated OS command injection flaw (CWE-78) in D-Link DIR-820 router firmware DIR820LA1_FW105B03, located in the ping.ccp web interface. A remote attacker with no credentials can send a crafted ping_addr parameter to ping.ccp, causing arbitrary operating-system commands to execute on the router. Successful exploitation escalates privileges to root, giving an attacker full control of the device for use as a botnet node or a foothold into the connected network. Users running the affected D-Link DIR-820 hardware are exposed, and because the product is end-of-life/end-of-service, fixes are not expected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-30, EPSS puts the 30-day exploitation probability at 97.9% (100th percentile), a public proof-of-concept is available, and active botnet campaigns such as RondoDox and Mirai-style campaigns are targeting flaws in this class of IoT devices.

Do: Per CISA's KEV required action, discontinue use of this end-of-life/end-of-service product — retire or replace the DIR-820, since no patched firmware is expected. If replacement must be delayed, restrict the router's web interface so it is not reachable from the WAN, disable remote management, and monitor for signs of botnet infection such as unusual outbound traffic. When inventorying, verify installed firmware version (affected build: DIR820LA1_FW105B03).

9.898% KEV PoC
  • D-Link DIR-820 (DIR-820L) router DIR8LA1_FW105B03 firmware (the version named in the advisory; no other version ranges were specified)
moderatelikely tens of thousands of internet-exposed units (estimated; no authoritative public scan count for this single end-of-life model)
CVE-2022-44928
+1 in the same advisory: …44929
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

NVD description · AI analysis pending
9.83% PoC
  • d-link dvg-g5402sp firmware
CVE-2022-40799
Unsigned Code Download Enables OS Command Execution in D-Link DNR-322L NVR

CVE-2022-40799 is a download-of-code-without-integrity-check flaw (CWE-494) in the D-Link DNR-322L network video recorder, which accepts and runs downloaded code without verifying it is authentic and unmodified. An attacker who already holds valid credentials on the device can trigger download and execution of unsigned code, gaining the ability to issue operating-system-level commands on the NVR. Successful exploitation yields control of the recorder, its stored camera footage, and a foothold for further attacks on the surveillance network. Only D-Link DNR-322L deployments are affected, and the product is end-of-life/end-of-service, so owners should expect limited or no vendor remediation and are advised to discontinue use. Exploitation is confirmed: CISA added the flaw to the KEV catalog on 2025-08-05, EPSS puts the 30-day exploitation probability at 31.7% (98th percentile), and no public proof-of-concept is known.

Do: Inventory your environment for DNR-322L recorders and, per CISA's required action, apply any mitigations D-Link has published or retire the device, since the product is EoL/EoS and the vendor recommends discontinuing use. If the recorder must stay in service, keep its management interface off the public internet behind a firewall and monitor for signs of command execution; federal agencies must remediate or discontinue use in line with BOD 22-01 deadlines.

8.834% KEV PoC
  • D-Link DNR-322L Network Video Recorder
moderatelikely low tens of thousands of surviving units worldwide, of which only a few thousand are internet-exposed
CVE-2016-20017
Unauthenticated Command Injection in D-Link DSL-2750B Router login.cgi

D-Link DSL-2750B routers running firmware before 1.05 contain an unauthenticated command injection flaw (CWE-77) in the 'cli' parameter of the login.cgi web endpoint. An attacker can trigger it remotely by sending a crafted HTTP request to login.cgi with shell metacharacters embedded in the cli parameter, requiring no credentials or user interaction. Successful exploitation yields arbitrary command execution on the router, giving the attacker full control of the device, which can be used for traffic interception, persistence, or recruitment into botnets such as the Mirai-based IZ1H9 campaign noted in recent reporting. Any internet-facing DSL-2750B running affected firmware is exposed, and CISA added the issue to the Known Exploited Vulnerabilities catalog on 2024-01-08 after exploitation observed in the wild from 2016 through 2022. With a CVSS of 9.8 and an EPSS of ~65%, exploitation pressure on unpatched devices remains high.

Do: Upgrade DSL-2750B firmware to version 1.05 or later per vendor instructions; if an update is unavailable or the device is end-of-life, follow CISA's required action and discontinue use or restrict web (HTTP) management access to trusted networks only. Defenders should check device logs for suspicious unauthenticated requests to login.cgi containing shell metacharacters in the cli parameter, as these indicate exploitation attempts.

9.865% KEV PoC ×2
  • D-Link DSL-2750B firmware before 1.05
largetens of thousands to ~100,000 internet-exposed DSL-2750B routers
CVE-2022-37055
Unauthenticated Buffer Overflow in D-Link GO-RT-AC750 Router Firmware

CVE-2022-37055 is a buffer overflow (CWE-120) in the cgibin binary's hnap_main handler on D-Link GO-RT-AC750 routers running GORTAC750_revA_v101b03 or GO-RT-AC750_revB_FWv200b02 firmware. Because the flaw sits in the router's HNAP/web management interface and requires no authentication, a remote attacker can trigger it with crafted network requests sent directly to the device. Successful exploitation can corrupt memory and is scored critical (CVSS 3.1: 9.8), giving the attacker potential full control of the router with high confidentiality, integrity, and availability impact. Owners of these specific GO-RT-AC750 (rev A and rev B) firmware releases are affected, and the broader context of active Mirai-family botnet campaigns targeting Linux-based edge devices raises the risk of automated mass exploitation. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-12-08, confirming exploitation in the wild, and its EPSS of 55.5% (99th percentile) indicates a high near-term probability of exploitation.

Do: Check GO-RT-AC750 (rev A and rev B) devices for the listed firmware versions and apply D-Link's mitigations or updated firmware per vendor instructions; if no fixed firmware is available, discontinue use of the device. Reduce exposure immediately by disabling HNAP, blocking remote management, or restricting the router's web interface to trusted networks, since exploitation requires no credentials. Federal agencies should follow BOD 22-01 timelines for remediation.

9.856% KEV PoC
  • D-Link GO-RT-AC750 (rev A) router firmware GORTAC750_revA_v101b03
  • D-Link GO-RT-AC750 (rev B) router firmware GO-RT-AC750_revB_FWv200b02
largelikely tens of thousands of internet-exposed units (public scans repeatedly find large populations of HNAP-enabled D-Link consumer routers; exact counts for…
CVE-2022-26258
Unauthenticated Remote Command Execution in D-Link DIR-820L Router

CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices.

Do: Because the DIR-820L is end-of-life and CISA's required action is to disconnect it if still in use, replace or retire the router; check the model and firmware version on the device's status/admin page (1.05B03 is confirmed vulnerable). If replacement is not immediate, disconnect the device from the internet or restrict exposure with firewall rules so the HTTP management interface is not reachable by untrusted hosts, and watch for Mirai-variant (MooBot) botnet traffic patterns. No fixed firmware version is provided in the available data, so upgrading alone is not a documented remedy.

9.892% KEV PoC ×2
  • D-Link DIR-820L router firmware 1.05B03 confirmed affected; the product is end-of-life and no fixed version is specified in the available data
large≈10,000–100,000 internet-exposed DIR-820L devices (order-of-magnitude estimate; a widely sold but end-of-life consumer router)
CVE-2021-45382
Command Injection RCE in D-Link DIR-810L/820L/826L/830L/836L Routers

A command injection flaw (CWE-78) in the Dynamic DNS (DDNS) handling of the ncc2 binary allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers. Because the DDNS function passes attacker-controlled input to a system shell without sanitization, a crafted request to the router's web service triggers command execution with the device's privileges (CVSS 9.8, AV:N/AC:L/PR:N/UI:N). A successful attacker gains full control of the router, enabling botnet enrollment, traffic interception, or pivoting into the local network. All hardware revisions of these five consumer/SOHO routers are affected, and because every model has reached End of Life/End of Service Life, D-Link will not issue patches. The flaw carries a 97.8% EPSS score, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-04, and has a public proof-of-concept, indicating active in-the-wild exploitation.

Do: Replace or retire any in-use DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, or DIR-836L router, as no firmware patch will be released. If replacement must wait, disable the DDNS feature and WAN-facing remote management, and verify the admin interface is not reachable from the internet. CISA's required action is to disconnect these end-of-life devices if they are still in service.

9.898% KEV PoC
  • D-Link DIR-810L firmware all hardware revisions, all firmware versions (EOL/EOS, no patch)
  • D-Link DIR-820L firmware all hardware revisions, all firmware versions (EOL/EOS, no patch)
  • D-Link DIR-820LW firmware all hardware revisions, all firmware versions (EOL/EOS, no patch)
  • +3 more
largetens of thousands of internet-exposed units; combined installed base of the five EOL models plausibly in the hundreds of thousands
CVE-2021-33259
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

NVD description · AI analysis pending
5.32% PoC
  • d-link dir-868lw firmware
CVE-2021-40655
Unauthenticated credential disclosure in D-Link DIR-605 router (getcfg.php)

CVE-2021-40655 is an unauthenticated information-disclosure flaw (CWE-863, incorrect authorization) in D-Link DIR-605 routers running B2 hardware revision firmware version 2.01MT. An attacker can trigger it remotely by forging a crafted POST request to the device's /getcfg.php page, with no credentials or user interaction required. The flaw returns the router's user name and password, giving the attacker valid credentials for the device's management interface and exposing confidential configuration data; the CVSS 7.5 score reflects high confidentiality impact with no direct integrity or availability impact. Only the legacy DIR-605 is affected, and per CISA all associated hardware revisions have reached end-of-life/end-of-service, so no fixed firmware should be expected from the vendor. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-05-16 amid headlines warning of actively exploited D-Link router flaws, a public proof-of-concept exists on GitHub, and EPSS assigns an 86.7% probability of exploitation within 30 days (percentile 100); ransomware use is unknown.

Do: Because the DIR-605 is end-of-life/end-of-service with no fixed firmware available, CISA's required action is to retire and replace affected units per vendor instructions. As interim mitigation, restrict or disable WAN-side (internet-facing) management so /getcfg.php is unreachable from the internet, and rotate any exposed administrative credentials. Defenders with internet-facing D-Link routers should inventory against this KEV entry and prioritize replacement of remaining DIR-605 units.

7.587% KEV PoC
  • D-Link DIR-605 router, B2 hardware revision (CPE entry: dir-605l firmware) Firmware 2.01MT
largetens of thousands of internet-exposed legacy units (estimated; the historical deployed base is likely far larger)
CVE-2021-41503
DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control.

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

NVD description · AI analysis pending
8.0<1%
  • dlink dcs-932l firmware
  • dlink dcs-5000l firmware
CVE-2021-26709
D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device

D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

NVD description · AI analysis pending
9.840% PoC
  • d-link dsl-320b-d1
CVE-2020-25506
Command Injection in D-Link DNS-320 system_mgr.cgi Allows Remote Code Execution

CVE-2020-25506 is an operating system command injection flaw (CWE-78) in the system_mgr.cgi component of D-Link DNS-320 network-attached storage devices. An attacker can trigger it by sending crafted input to the system_mgr.cgi handler of the device's web management interface, causing attacker-controlled data to be executed as operating system commands. Successful exploitation may allow remote code execution on the NAS, giving an attacker control over the device and its stored data. Any D-Link DNS-320 running affected firmware is at risk; the available data does not specify affected or fixed version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and current EPSS assigns roughly a 100% probability of exploitation within 30 days, though a specific ransomware association has not been confirmed.

Do: Apply D-Link firmware updates for the DNS-320 per the vendor's instructions, as required by CISA's KEV listing. Until patched, stop exposing the device's web interface to the internet (remove port forwarding/DMZ rules or restrict access to trusted management networks). Because exploitation is being observed, check NAS logs for unexpected requests to system_mgr.cgi and signs of unauthorized command execution.

9.8100% KEV PoC
  • D-Link DNS-320 (network-attached storage device)
largetens of thousands of internet-exposed DNS-320 devices (estimate; total installed base likely higher)
CVE-2020-29557
Pre-Authentication Buffer Overflow RCE in D-Link DIR-825 R1 Routers

CVE-2020-29557 is a critical buffer overflow (CVSS 9.8) in the web interface of D-Link DIR-825 R1 routers running firmware through 3.0.1. Because the flaw is reachable without authentication, a remote attacker can send crafted requests to the router's HTTP management interface and trigger the overflow to execute arbitrary code on the device. Successful exploitation gives the attacker full control of the router, typically enabling traffic interception, further network compromise, or use of the device as an attack pivot or botnet node. Any DIR-825 R1 device whose management interface is reachable — especially units exposed directly to the internet — is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities (added 2021-11-03) and a public proof-of-concept exists, indicating exploitation in the wild.

Do: Upgrade DIR-825 R1 devices to the fixed firmware released on 2020-11-20 or later, per D-Link's update instructions. Until patched, restrict or disable web-based administration from the WAN side and allow management access only from trusted networks. Given the KEV listing and ~54% EPSS, prioritize internet-facing units and review router logs for signs of compromise.

9.854% KEV PoC
  • D-Link DIR-825 R1 firmware all versions through 3.0.1 (fixed by vendor update released 2020-11-20)
largeon the order of tens of thousands of internet-exposed devices (estimate)
CVE-2020-25079
+1 in the same advisory: …25078
Authenticated Command Injection in D-Link DCS-2530L and DCS-2670L Cameras

D-Link DCS-2530L and DCS-2670L IP camera firmware contains an authenticated command injection flaw (CWE-77) in the cgi-bin/ddns_enc.cgi endpoint, which handles dynamic DNS (DDNS) configuration. An attacker with valid credentials for the camera's web interface (default or weak passwords are common on consumer cameras) can submit crafted input through this endpoint to execute arbitrary operating-system commands on the device; the CVSS 3.1 score of 8.8 reflects network reachability, low privilege required, no user interaction, and high confidentiality, integrity, and availability impact. Successful compromise gives the attacker control of the camera, access to its video feed, and a potential foothold for pivoting into the network the camera sits on. The affected population is DCS-2530L units on firmware before 1.06.01 Hotfix and DCS-2670L units on firmware through 2.02, typically deployed in homes and small-business settings. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid evidence of active exploitation, and EPSS assigns it a 52.7% probability of exploitation within 30 days (99th percentile).

Do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and DCS-2670L cameras to a post-2.02 firmware/hotfix per D-Link's advisory; since these are older consumer models that may no longer receive updates, replace or retire units that cannot be patched. Because exploitation requires valid credentials, enforce strong non-default passwords, remove internet-facing port forwarding/UPnP exposure of the cameras' web interfaces, and restrict management access to trusted networks; U.S. federal agencies should follow the applicable BOD 22-01 guidance or discontinue use if mitigations are unavailable. Given the KEV listing, check exposed units for signs of compromise such as modified settings or unexpected outbound connections.

8.8
group max
56% KEV PoC
  • D-Link DCS-2530L firmware before 1.06.01 Hotfix
  • D-Link DCS-2670L firmware through 2.02 (fix requires firmware beyond 2.02 per vendor)
  • D-Link DCS-4703E firmware
  • +6 more
moderateplausibly tens of thousands of deployed units worldwide, with likely only low thousands directly internet-exposed (estimate)
CVE-2019-6258
D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP protocol messag

D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP protocol message, which is mishandled in /usr/sbin/udhcpd during reading of the /var/servd/LAN-1-udhcpd.conf file.

NVD description · AI analysis pending
9.83% PoC
  • d-link dir-822 firmware
CVE-2020-15633
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with fir

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.20B10_BETA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP requests. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the router. Was ZDI-CAN-10835.

NVD description · AI analysis pending
8.83%
  • d-link dir-867 firmware
  • d-link dir-878 firmware
  • d-link dir-882 firmware
CVE-2020-9377
OS Command Injection RCE in D-Link DIR-610 Routers

D-Link DIR-610 routers contain an OS command injection flaw (CWE-78) in command.php, where the cmd parameter is passed to the underlying operating system without adequate sanitization, allowing remote attackers to execute arbitrary commands on the device. The flaw is triggered by sending a crafted HTTP request to command.php with a malicious cmd parameter. Successful exploitation yields remote command execution on the router, which an attacker can leverage for device takeover or as a foothold into the network behind it. Only D-Link DIR-610 devices, a consumer router line that has reached end-of-life, are affected. The vulnerability is listed in the CISA KEV catalog (added 2022-03-25), indicating it is being exploited in the wild, and its high EPSS percentile (97th, 21.3% probability of exploitation in 30 days) reinforces elevated risk despite no known public proof-of-concept.

Do: Disconnect or replace DIR-610 routers, which are end-of-life, consistent with CISA's required action; no fixed firmware version is specified in the available data. If replacement is not immediate, block WAN access to the router web interface (including command.php) and review logs for suspicious requests carrying a cmd parameter that could indicate compromise.

8.821% KEV PoC ×2
  • D-Link DIR-610 devices
moderateLikely a few thousand internet-exposed units (estimate; no public scan count specific to DIR-610)
CVE-2016-11021
Authenticated OS Command Injection in D-Link DCS-930L Cameras Allows RCE

D-Link DCS-930L network cameras running firmware versions before 2.12 contain an OS command injection flaw (CWE-78) in the setSystemCommand handler. An attacker with access to the camera's web interface (the CVSS vector requires high privileges, indicating an authenticated, admin-level request) submits an operating-system command in the SystemCommand parameter, and the device executes it without proper validation. Successful exploitation yields remote code execution on the camera, enabling device takeover, pivoting into the local network, or recruitment into IoT botnets such as BotenaGo, which bundles 33 exploits targeting millions of consumer IoT devices. Any DCS-930L deployment on pre-2.12 firmware is affected, and the product is end-of-life, so CISA's required action is to disconnect it if still in use. The flaw is listed in CISA's KEV catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries a 68.9% EPSS probability of exploitation within 30 days (99th percentile), indicating confirmed in-the-wild exploitation; ransomware use is unknown.

Do: Update affected DCS-930L cameras to firmware 2.12 or later if obtainable; because the product is end-of-life, CISA's required action is to disconnect or retire any unit still in service. Until remediated, keep the camera's management interface off direct internet exposure and restrict administrative access. Verify the running firmware version and watch for signs of compromise such as unexpected outbound traffic.

7.269% KEV PoC
  • D-Link DCS-930L network camera firmware All firmware versions before 2.12 (fixed in 2.12)
largetens of thousands of internet-exposed cameras (millions of units sold historically; many EOL devices still deployed)
CVE-2020-9544
An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices.

An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their choice.

NVD description · AI analysis pending
7.51% PoC
  • d-link dsl-2640b firmware
CVE-2019-20500
Authenticated OS Command Injection in D-Link DWL-2600AP Access Point Web Interface

D-Link DWL-2600AP access points running firmware 4.2.0.15 Rev A contain an authenticated OS command injection flaw (CWE-78) in the web interface's Save Configuration function (admin.cgi?action=config_save). An attacker with valid credentials submits shell metacharacters in the configBackup or downloadServerip parameters, causing arbitrary operating-system commands to execute on the device. Successful exploitation yields command execution on the access point itself, which can be used to pivot into the local network or to conscript the device into botnets, consistent with the recently reported Mirai campaign targeting multiple IoT device flaws. Any organization still running the affected DWL-2600AP hardware is exposed, especially where the management web interface is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-29, confirming active in-the-wild exploitation, and it carries a very high EPSS (~97%) alongside a public proof-of-concept (Exploit-DB 46841).

Do: Inventory all DWL-2600AP units, identify devices on the vulnerable firmware revision, and apply D-Link's latest available firmware per vendor instructions; because this product line is end-of-life, CISA's required action explicitly permits discontinuing use of the product if updates are unavailable. In the interim, restrict access to the web management interface (admin.cgi) to trusted management networks, remove any internet exposure, and ensure default or shared administrator credentials have been changed, since exploitation requires authentication.

7.897% KEV PoC
  • D-Link DWL-2600AP Access Point (firmware) 4.2.0.15 Rev A (the revision named in the advisory; no broader affected version range is specified)
moderate≈ thousands to low tens of thousands of deployed devices worldwide (order-of-magnitude estimate; EOL product)
CVE-2019-17621
Unauthenticated Root Command Injection in D-Link DIR-859 Router UPnP

CVE-2019-17621 is an unauthenticated OS command injection flaw (CWE-78) in the UPnP endpoint /gena.cgi of D-Link DIR-859 Wi-Fi router firmware 1.05 and 1.06B01 Beta01. An attacker who can reach the UPnP service — typically by being on the local network — sends a specially crafted HTTP SUBSCRIBE request that injects and executes system commands. Because the service runs with root privileges, successful exploitation gives the attacker full control of the router, enabling configuration changes, traffic manipulation, and recruitment into botnets such as Mirai. The CISA-affected product is the DIR-859, with related D-Link DIR-series router firmware also listed in the CPE data, and public proof-of-concept references are available. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-29, and current headlines describe Mirai botnet campaigns leveraging it among multiple IoT flaws.

Do: Apply the latest D-Link firmware updates per vendor instructions; because the DIR-859 is an older model that may no longer receive updates, CISA's required action is to discontinue use of the product if a fixed release is unavailable. If the router is not at end of life, restrict or disable UPnP where unused and ensure the UPnP endpoint is not reachable beyond the LAN, then check for signs of botnet compromise such as unusual outbound traffic or unauthorized configuration changes.

9.890% KEV PoC ×2
  • D-Link DIR-859 Wi-Fi router firmware 1.05 and 1.06B01 Beta01 (per CVE description; CISA-affected product)
  • D-Link DIR-822 firmware
  • D-Link DIR-823 firmware
  • +9 more
large≈100k–1M deployed routers (order-of-magnitude estimate)
CVE-2019-17663
D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

NVD description · AI analysis pending
6.1<1%
  • d-link dir-866l firmware
CVE-2019-16920
Command Injection in Multiple D-Link Routers Enables Full Device Compromise

Multiple D-Link routers contain a command injection flaw (CWE-78) in which attacker-controlled input is executed as operating system commands by the device. An attacker who triggers the flaw can run arbitrary commands on the router with system privileges, achieving full compromise of the device, from which they can intercept or redirect traffic, pivot to the local network, or persist on the device. The specific affected models and firmware version ranges are not enumerated in the available data, but CISA notes the impacted product line is end-of-life, so only devices still in service are at risk. This vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing means defenders should treat exploitation as active, not theoretical.

Do: Inventory your environment for D-Link routers and identify any running the affected end-of-life models; per CISA's required action, disconnect or retire them if still in use since they no longer receive fixes. If a device must remain in service, restrict management access (disable WAN-side web administration, limit it to trusted management networks) and monitor for compromise indicators. Confirm whether any internet-facing D-Link routers are exposed and prioritize replacement of EOL units.

9.8100% KEV PoC ×2
  • D-Link
massplausibly hundreds of thousands of internet-exposed D-Link routers and millions sold overall; exact count of in-use affected units unknown
CVE-2019-16057
Unauthenticated RCE via Command Injection in D-Link DNS-320 NAS

CVE-2019-16057 is a remote command injection flaw (CWE-78) in the login_mgr.cgi script of D-Link DNS-320 NAS firmware through version 2.05.B10. An attacker can trigger it by sending a crafted, unauthenticated HTTP request to login_mgr.cgi, causing injected operating-system commands to execute on the device. Successful exploitation yields full remote code execution on the NAS, giving the attacker control over stored data and a network foothold that can enable lateral movement or ransomware staging. Any D-Link DNS-320 running vulnerable firmware is affected, with directly internet-exposed units at greatest risk. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) with known ransomware use, a public proof-of-concept is available, and EPSS puts the 30-day exploitation probability at 87.1%.

Do: Per CISA's required action, the DNS-320 is end-of-life and should be disconnected from the network if still in use, prioritizing any unit reachable from the internet. Check D-Link's support site for any final firmware release before retiring the device, and audit retained units for signs of compromise (unexpected processes or outbound connections) given known ransomware use.

9.887% KEV ransomware PoC
  • D-Link DNS-320 Storage Device (ShareCenter NAS) firmware through 2.05.B10
largeorder of tens of thousands of internet-exposed DNS-320 devices (≈10,000–100,000 units; estimate)
CVE-2018-19989
+1 in the same advisory: …19990
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

NVD description · AI analysis pending
9.86% PoC
  • d-link dir-822 firmware
CVE-2018-19988
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 d

In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. It needs to bypass the wget command option with a single quote. A vulnerable /HNAP1/SetClientInfoDemo XML message could have single quotes and backquotes in the AudioMute or AudioEnable element, such as the '`telnetd`' string.

NVD description · AI analysis pending
9.87% PoC
  • d-link dir-868l firmware
CVE-2018-19986
+1 in the same advisory: …19987
In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 20

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.

NVD description · AI analysis pending
9.842% PoC
  • d-link dir-818lw firmware
  • d-link dir-822 firmware
CVE-2018-19300
On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

NVD description · AI analysis pending
9.874% PoC
  • d-link dap-1530 firmware
  • d-link dap-1610 firmware
  • d-link dwr-111 firmware
  • +1 more
CVE-2019-9125
+1 in the same advisory: …9124
An issue was discovered on D-Link DIR-878 1.12B01 devices.

An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.

NVD description · AI analysis pending
9.83% PoC ×2
  • d-link dir-878 firmware
CVE-2019-7297
An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03.

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.

NVD description · AI analysis pending
9.812% PoC
  • d-link dir-823g firmware
CVE-2018-20389
D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1

D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

NVD description · AI analysis pending
9.82% PoC
  • d-link dcm-604 firmware
  • d-link dcm-704 firmware
CVE-2018-18767
An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06.

An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.

NVD description · AI analysis pending
7.0<1% PoC
  • dlink mydlink baby camera monitor
  • dlink dcs-825l firmware
CVE-2018-18442
D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks.

D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., live-online video/audio streaming) by using the hping3 tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding, UDP flooding, ICMP flooding, and SYN-ACK flooding.

NVD description · AI analysis pending
7.51% PoC
  • d-link dcs-825l firmware
CVE-2018-18441
D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration.

D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: /common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hw_version, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.

NVD description · AI analysis pending
7.52% PoC
  • d-link dcs-936l firmware
  • d-link dcs-942l firmware
  • d-link dcs-8000lh firmware
  • +1 more
CVE-2018-20305
D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter.

D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.

NVD description · AI analysis pending
9.84% PoC
  • d-link dir-816 a2 firmware
CVE-2018-20056
+1 in the same advisory: …20057
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices.

An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. There is a stack-based buffer overflow allowing remote attackers to execute arbitrary code without authentication via the goform/formLanguageChange currTime parameter.

NVD description · AI analysis pending
9.8
group max
7% PoC
  • d-link dir-619l firmware
  • d-link dir-605l firmware
CVE-2018-18636
XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.

XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.

NVD description · AI analysis pending
6.11% PoC ×2
  • d-link dsl-2640t firmware
CVE-2018-14081
+1 in the same advisory: …14080
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices.

An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext.

NVD description · AI analysis pending
9.8
group max
1%
  • d-link dir-809 a1 firmware
  • d-link dir-809 a2 firmware
  • d-link dir-809 guestzone firmware
CVE-2018-17881
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password ch

On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.

NVD description · AI analysis pending
9.82% PoC
  • d-link dir-823g firmware