Skip to content
COOEY

FAIL › dossier

D-Link

VENDOR

· dossier confidence 60%

D-Link is a major networking vendor with a critically poor security track record defined by repeated remote code execution vulnerabilities in consumer firmware. Their history of unpatched RCEs, command injection flaws, and hard-coded credentials in DIR-800 and DNS-300 series devices poses severe risk for CMMC environments requiring strict supply chain security.

PROFILE
CategorynetworkingWhat they doD-Link is a major networking vendor that designs, manufactures, and sells consumer and enterprise networking equipment including routers, switches, and access points.Founded1986HQTaiwan Websitehttps://www.dlink.com ↗
SECURITY POSTURE

D-Link exhibits a critically poor security posture characterized by a persistent pattern of unpatched remote code execution (RCE) vulnerabilities across consumer firmware, particularly in DIR-800 and DNS-300 series devices, with multiple critical CVEs remaining unpatched for years.

Notable failures
  • CVE-2018-6530 critical RCE in multiple routers
  • CVE-2019-16057 critical RCE in DNS-320 login_mgr.cgi
  • CVE-2024-3272 hard-coded credentials enabling authenticated command injection
  • CVE-2025-29635 high RCE in DIR-823X router
  • CVE-2026-15270 high privilege escalation in DIR-823G web interface
Patterns: repeated unpatched edge-device RCEs; hard-coded credentials in firmware; command injection via CGI endpoints; buffer overflows in web interfaces; long unpatched lifecycles for consumer firmware
FAILURE HISTORY · 26
DATEEVENTSEVSUMMARY
2022-04-15 CVE-2019-16057 critical A critical, actively exploited remote code execution vulnerability existed in D-Link's DNS-320 storage device, allowing attackers to execute arbitrary code remotely.
2024-09-30 CVE-2023-25280 high D-Link DIR-820 routers allow remote, unauthenticated attackers to escalate privileges to root via OS command injection in the ping_addr parameter.
2024-04-11 CVE-2024-3272 high D-Link NAS devices contain hard-coded credentials enabling authenticated command injection and remote code execution.
2024-01-08 CVE-2016-20017 high D-Link DSL-2750B devices allow remote, unauthenticated command injection via login.cgi, enabling arbitrary code execution.
2022-09-08 CVE-2018-6530 critical D-Link routers suffer from an actively exploited OS command injection flaw that allows remote code execution.
2022-04-04 CVE-2021-45382 high D-Link routers shipped with a remote code execution flaw in the DDNS function that was actively exploited in the wild.
2022-03-25 CVE-2019-16920 high D-Link routers had a command injection flaw allowing full system compromise.
2022-03-25 CVE-2016-11021 high A remote attacker can execute arbitrary OS commands on D-Link DCS-930L devices via the setSystemCommand function.
2022-02-10 CVE-2015-2051 high D-Link DIR-645 routers allow remote attackers to execute arbitrary commands via the HNAP interface, a flaw actively exploited in the wild.
2021-11-03 CVE-2020-25506 high D-Link DNS-320 devices suffer from an unpatched command injection vulnerability enabling remote code execution.
2021-11-03 CVE-2020-29557 high D-Link DIR-825 R1 devices have an unpatched buffer overflow in their web interface allowing remote code execution.
2025-12-08 CVE-2022-37055 high D-Link routers exploited for buffer overflow, impact high
2025-08-05 CVE-2020-25078 high D-Link's DCS-2530L and DCS-2670L devices exposed to remote admin password disclosure.
2025-08-05 CVE-2020-25079 high D-Link's DCS-2530L and DCS-2670L devices had unpatched command injection vulnerabilities actively exploited in the wild.
2025-08-05 CVE-2022-40799 high D-Link DNR-322L exposed to authenticated RCE due to lack of integrity checks on code downloads.
2025-06-25 CVE-2024-0769 high D-Link DIR-859 Router exposed due to unpatched path traversal vulnerability, enabling potential unauthorized control.
2022-09-08 CVE-2022-26258 high D-Link DIR-820L exposed to RCE due to unpatched vulnerability
2022-09-08 CVE-2011-4723 high D-Link DIR-300 stored passwords in plaintext, allowing attackers to access sensitive data.
2022-03-25 CVE-2020-9377 high D-Link DIR-610 devices allow remote code execution via an unpatched vulnerability in command.php.
2026-04-24 CVE-2025-29635 high D-Link DIR-823X router allows remote command execution via POST request to /goform/set_prohibiting endpoint.
2024-05-16 CVE-2021-40655 high D-Link DIR-605 routers allow attackers to extract admin credentials via forged POST requests to /getcfg.php.
2024-04-11 CVE-2024-3273 high D-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L) have a command injection vulnerability that enables remote code execution when combined with CVE-2024-3272.
2023-06-29 CVE-2019-17621 high A D-Link router allowed unauthenticated attackers to execute commands as root via a UPnP vulnerability, now actively exploited in the wild.
2023-06-29 CVE-2019-20500 high A D-Link access point had a command injection vulnerability allowing unauthorized code execution via its web interface, actively exploited in the wild.
2022-03-25 CVE-2013-5223 high D-Link DSL-2760U gateway XSS flaw lets authenticated attackers inject scripts, exposing data and violating CMMC data integrity controls.
2024-05-16 CVE-2014-100005 high D-Link DIR-600 routers contain a CVE-2014-100005 CSRF vulnerability that allows attackers to hijack admin sessions and change router configurations.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-0.70
"…"
Open questions: D-Link's current patch management process for end-of-life devices · D-Link's current security posture for enterprise-grade products
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:10:13.867969+00:00