FAIL › dossier
D-Link
VENDOR· dossier confidence 60%
D-Link is a major networking vendor with a critically poor security track record defined by repeated remote code execution vulnerabilities in consumer firmware. Their history of unpatched RCEs, command injection flaws, and hard-coded credentials in DIR-800 and DNS-300 series devices poses severe risk for CMMC environments requiring strict supply chain security.
PROFILE
CategorynetworkingWhat they doD-Link is a major networking vendor that designs, manufactures, and sells consumer and enterprise networking equipment including routers, switches, and access points.Founded1986HQTaiwan
Websitehttps://www.dlink.com ↗
SECURITY POSTURE
D-Link exhibits a critically poor security posture characterized by a persistent pattern of unpatched remote code execution (RCE) vulnerabilities across consumer firmware, particularly in DIR-800 and DNS-300 series devices, with multiple critical CVEs remaining unpatched for years.
Notable failures
- CVE-2018-6530 critical RCE in multiple routers
- CVE-2019-16057 critical RCE in DNS-320 login_mgr.cgi
- CVE-2024-3272 hard-coded credentials enabling authenticated command injection
- CVE-2025-29635 high RCE in DIR-823X router
- CVE-2026-15270 high privilege escalation in DIR-823G web interface
Patterns: repeated unpatched edge-device RCEs; hard-coded credentials in firmware; command injection via CGI endpoints; buffer overflows in web interfaces; long unpatched lifecycles for consumer firmware
FAILURE HISTORY · 26
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-15 | CVE-2019-16057 | critical | A critical, actively exploited remote code execution vulnerability existed in D-Link's DNS-320 storage device, allowing attackers to execute arbitrary code remotely. |
| 2024-09-30 | CVE-2023-25280 | high | D-Link DIR-820 routers allow remote, unauthenticated attackers to escalate privileges to root via OS command injection in the ping_addr parameter. |
| 2024-04-11 | CVE-2024-3272 | high | D-Link NAS devices contain hard-coded credentials enabling authenticated command injection and remote code execution. |
| 2024-01-08 | CVE-2016-20017 | high | D-Link DSL-2750B devices allow remote, unauthenticated command injection via login.cgi, enabling arbitrary code execution. |
| 2022-09-08 | CVE-2018-6530 | critical | D-Link routers suffer from an actively exploited OS command injection flaw that allows remote code execution. |
| 2022-04-04 | CVE-2021-45382 | high | D-Link routers shipped with a remote code execution flaw in the DDNS function that was actively exploited in the wild. |
| 2022-03-25 | CVE-2019-16920 | high | D-Link routers had a command injection flaw allowing full system compromise. |
| 2022-03-25 | CVE-2016-11021 | high | A remote attacker can execute arbitrary OS commands on D-Link DCS-930L devices via the setSystemCommand function. |
| 2022-02-10 | CVE-2015-2051 | high | D-Link DIR-645 routers allow remote attackers to execute arbitrary commands via the HNAP interface, a flaw actively exploited in the wild. |
| 2021-11-03 | CVE-2020-25506 | high | D-Link DNS-320 devices suffer from an unpatched command injection vulnerability enabling remote code execution. |
| 2021-11-03 | CVE-2020-29557 | high | D-Link DIR-825 R1 devices have an unpatched buffer overflow in their web interface allowing remote code execution. |
| 2025-12-08 | CVE-2022-37055 | high | D-Link routers exploited for buffer overflow, impact high |
| 2025-08-05 | CVE-2020-25078 | high | D-Link's DCS-2530L and DCS-2670L devices exposed to remote admin password disclosure. |
| 2025-08-05 | CVE-2020-25079 | high | D-Link's DCS-2530L and DCS-2670L devices had unpatched command injection vulnerabilities actively exploited in the wild. |
| 2025-08-05 | CVE-2022-40799 | high | D-Link DNR-322L exposed to authenticated RCE due to lack of integrity checks on code downloads. |
| 2025-06-25 | CVE-2024-0769 | high | D-Link DIR-859 Router exposed due to unpatched path traversal vulnerability, enabling potential unauthorized control. |
| 2022-09-08 | CVE-2022-26258 | high | D-Link DIR-820L exposed to RCE due to unpatched vulnerability |
| 2022-09-08 | CVE-2011-4723 | high | D-Link DIR-300 stored passwords in plaintext, allowing attackers to access sensitive data. |
| 2022-03-25 | CVE-2020-9377 | high | D-Link DIR-610 devices allow remote code execution via an unpatched vulnerability in command.php. |
| 2026-04-24 | CVE-2025-29635 | high | D-Link DIR-823X router allows remote command execution via POST request to /goform/set_prohibiting endpoint. |
| 2024-05-16 | CVE-2021-40655 | high | D-Link DIR-605 routers allow attackers to extract admin credentials via forged POST requests to /getcfg.php. |
| 2024-04-11 | CVE-2024-3273 | high | D-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L) have a command injection vulnerability that enables remote code execution when combined with CVE-2024-3272. |
| 2023-06-29 | CVE-2019-17621 | high | A D-Link router allowed unauthenticated attackers to execute commands as root via a UPnP vulnerability, now actively exploited in the wild. |
| 2023-06-29 | CVE-2019-20500 | high | A D-Link access point had a command injection vulnerability allowing unauthorized code execution via its web interface, actively exploited in the wild. |
| 2022-03-25 | CVE-2013-5223 | high | D-Link DSL-2760U gateway XSS flaw lets authenticated attackers inject scripts, exposing data and violating CMMC data integrity controls. |
| 2024-05-16 | CVE-2014-100005 | high | D-Link DIR-600 routers contain a CVE-2014-100005 CSRF vulnerability that allows attackers to hijack admin sessions and change router configurations. |
SENTIMENT · TRUSTED SOURCES
DOSSIER SOURCES
- D-Link Logo, symbol, meaning, history, PNG, brand - Logos-world · logos-world.net
- Dell Technologies (DELL) Company Profile & Description · stockanalysis.com
- Jabil (JBL) Company Profile & Description - Stock Analysis · stockanalysis.com
- CVE-2026-15270 - High Vulnerability - TheHackerWire · www.thehackerwire.com
- CVE-2026-15270 | High severity in D-link DIR-823G | CVETodo · cvetodo.com
- CPAI-2025-17894 - Check Point Software · advisories.checkpoint.com
- OpManager Upgrade Packs - ManageEngine · www.manageengine.com
- Investigating Co-Management Issues with Windows Endpoints in SCCM ... · eskonr.com
- Third-Party Software Support - Automox · docs.automox.com
Open questions: D-Link's current patch management process for end-of-life devices · D-Link's current security posture for enterprise-grade products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:10:13.867969+00:00