Skip to content
COOEY

FAIL › dossier

dlink

VENDOR

· dossier confidence 20%

D-Link is a major networking vendor with a critical security track record characterized by repeated RCE vulnerabilities in consumer firmware, particularly in DIR-816A2 and DIR-823G devices. Their history of command injection flaws in HNAP1 and firmware components poses significant risk for CMMC environments.

PROFILE
CategoryvendorWhat they doD-Link is a global networking equipment manufacturer specializing in Wi-Fi routers, modems, and IoT devices for residential and enterprise markets. Websitehttps://www.dlink.com ↗
SECURITY POSTURE

D-Link has a documented history of critical remote code execution (RCE) vulnerabilities in consumer-grade firmware, particularly in DIR-816A2, DIR-820L, and DIR-823G devices, with multiple command injection flaws discovered between 2021 and 2024.

Notable failures
  • CVE-2024-24321: RCE in DIR-816A2 wizardstep4_ssid_2 parameter
  • CVE-2023-39637: Command injection in DIR-816A2 /goform/Diagnosis
  • CVE-2022-26258: RCE in DIR-820L via HTTP POST to get set ccp
  • CVE-2020-25367: HNAP1 command injection in DIR-823G V1.0.2B05
  • CVE-2020-25368: HNAP1 command injection in DIR-823G V1.0.2B05
  • CVE-2021-42627: Unauthenticated WAN configuration access on DIR-615
Patterns: repeated unpatched edge-device RCEs; command injection in firmware components; HNAP1 protocol vulnerabilities
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2024-02-08 CVE-2024-24321 critical An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
2023-09-12 CVE-2023-39637 critical D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
2022-03-28 CVE-2022-26258 critical D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
2021-11-04 CVE-2020-25367 critical A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
2021-11-04 CVE-2020-25368 critical A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
2022-08-23 CVE-2021-42627 critical The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.
2022-05-23 CVE-2022-28932 critical D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
2021-11-04 CVE-2020-25366 critical An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.50
D-Link faced significant scrutiny for the command injection vulnerability in DIR-823G devices, with the vulnerability being tracked by multiple security databases and potentially impacting CISA KEV li
synthesissevere-fallout-0.80
D-Link's command injection flaw in DIR-823G firmware was widely flagged as critical, with active exploitation by threat actors and CISA warnings, indicating severe security fallout and vendor accounta
synthesisneutral-0.20
No vendor-specific coverage found for D-Link CVE-2020-25366 in provided sources
Irrelevant
"Hidden Backdoor in Tenda Router Firmware"
app.opencve.io ↗neutral+0.00
Irrelevant
"CVEs and Security Vulnerabilities - OpenCVE"
CISA ↗neutral+0.00
Irrelevant
"ICS Advisories | CISA"
Irrelevant
"Accenture Confirms Intrusion After Hacker Claims 35GB Data Breach"
NVD ↗neutral+0.00
Irrelevant
"NVD - Cve-2026-56291"
cooey ↗severe-fallout-0.30
Neutral
"A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05."
www.cvefind.com ↗severe-fallout+0.00
Neutral
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
www.databreachtoday.com ↗severe-fallout-0.20
Negative
"Hidden Backdoor in Tenda Router Firmware - DataBreachToday"
CISA ↗severe-fallout-0.40
Severe-fallout
"ICS Advisories | CISA"
classactionu.org ↗severe-fallout+0.00
Neutral
"Current Data Breaches Archive | Class Action U"
www.vulncheck.com ↗severe-fallout+0.00
Neutral
"VulnCheck Advisories"
Neutral
"Fines Database — GDPR Enforcement Tracker"
cooey ↗severe-fallout-0.90
Critical vulnerability disclosed
"A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login."
dailysecurityreview.com ↗severe-fallout+0.00
Irrelevant to D-Link
"ASUS Patches Critical Authentication Bypass Vulnerability in DSL Series Routers"
www.cvefind.com ↗severe-fallout+0.00
Irrelevant to D-Link
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
www.databreachtoday.com ↗severe-fallout+0.00
Irrelevant to D-Link
"Hidden Backdoor in Tenda Router Firmware - DataBreachToday"
dailysecurityreview.com ↗severe-fallout-0.90
Active exploitation and CISA warning
"TP-Link Router Vulnerabilities Actively Exploited by Hackers, CISA Urges Immediate Disconnection"
The Hacker News ↗severe-fallout+0.00
Irrelevant to D-Link
"Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot"
app.opencve.io ↗severe-fallout+0.00
Irrelevant to D-Link
"CVEs and Security Vulnerabilities - OpenCVE"
cooey ↗neutral+0.00
Neutral listing
"An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors."
Irrelevant
"ASUS Patches Critical Authentication Bypass Vulnerability in DSL Series Routers"
Open questions: D-Link's current patch management process for firmware updates · D-Link's compliance status with CMMC requirements
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:03:29.832331+00:00