Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · d-link

d-link

· 5 Critical

Total CVEs

113

Critical

5

Products

128

Search All CVEs →

113

Products (128)

dsl-3782 firmware7 CVEsdir-822 firmware5 CVEsdir-823g firmware5 CVEsdi-6044 CVEsdns-327l firmware3 CVEsdsl-g604t3 CVEsdsl-g624t3 CVEsdir-878 firmware3 CVEsdvg-n5402sp firmware3 CVEsdir-615 firmware3 CVEsdi-614\+3 CVEsdir-620 firmware3 CVEsdcs-825l firmware3 CVEsdnr-326 firmware3 CVEsdir-550a firmware2 CVEsdir-816 a2 firmware2 CVEsdcs-2103 hd cube network camera2 CVEsdns-320l firmware2 CVEsdir-600m firmware2 CVEsdir-868l firmware2 CVEsdir-604m firmware2 CVEsdl-7042 CVEsdcs-2103 hd cube network camera firmware2 CVEsdir-809 a2 firmware2 CVEsdir-880l firmware2 CVEsdvg-g5402sp2 CVEsdvg-g5402sp firmware2 CVEsdi-7842 CVEsdwl-1000ap2 CVEsdir-605l firmware2 CVEsdi-8042 CVEsdwl-900ap\+2 CVEsdir-809 a1 firmware2 CVEsdir-619l firmware2 CVEsdir-809 guestzone firmware2 CVEsdir-130 firmware2 CVEsdir-818lw firmware2 CVEsdph-5402 CVEsdph-5412 CVEsdap 2253 firmware2 CVEsdir-330 firmware2 CVEsdns-322l firmware2 CVEsdap 22532 CVEsdir-868lw firmware1 CVEsdir-882 firmware1 CVEsdir-885\/r1 CVEsdir-885l\/r firmware1 CVEsdir-885l firmware1 CVEsdir-890l\/r firmware1 CVEsdir-890l firmware1 CVEsdir-895\/r1 CVEsdir-895l\/r firmware1 CVEsdir-895l firmware1 CVEsdkvm-ip81 CVEsdnr-320l firmware1 CVEsdns-320b firmware1 CVEsdns-320lw firmware1 CVEsdns-325 firmware1 CVEsdns-345 firmware1 CVEsdp-3031 CVEsdsa-3100 airspot gateway1 CVEsdsl-2540u firmware1 CVEsdsl-2640b1 CVEsdsl-2640b firmware1 CVEsdsl-2640t firmware1 CVEsdsl-2640u firmware1 CVEsdsl-320b-d11 CVEsdsl-502t1 CVEsdsl-504t1 CVEsdsl-562t1 CVEsdsl6740u1 CVEsdsl6740u firmware1 CVEsdwl-2000ap\+1 CVEsdwl-2100ap1 CVEsdwl-g1321 CVEsdwl-g650\+1 CVEsdwl-g700ap1 CVEsdwr-116 firmware1 CVEsdwr-711 firmware1 CVEsebr-2310 ethernet broadband router1 CVEsmpeg4 shm audio control1 CVEsmydlink\+1 CVEstftp server1 CVEswbr-1310 wireless g router1 CVEsdap-1353 h\/w b1 firmware1 CVEswbr-2310 rangebooster g router1 CVEsdap-1530 firmware1 CVEsdap-1610 firmware1 CVEsdap-2553 h\/w a1 firmware1 CVEsdap-3520 h\/w a1 firmware1 CVEsdcm-604 firmware1 CVEsdcm-704 firmware1 CVEsdcs-2102 firmware1 CVEsdcs-2121 firmware1 CVEsdcs-2630l firmware1 CVEsdcs-5000l firmware1 CVEsdcs-5222l firmware1 CVEsdcs-5222lb1 firmware1 CVEsdcs-8000lh firmware1 CVEsdcs-8100lh firmware1 CVEsdcs-820l firmware1 CVEsdcs-855l firmware1 CVEsdcs-900 internet camera1 CVEsdcs-936l1 CVEsdcs-936l firmware1 CVEsdcs-942lb1 firmware1 CVEsdi-5241 CVEsdi-524 firmware1 CVEsdi-604 broadband router1 CVEsdi-6241 CVEsdi-704p1 CVEsdir-1001 CVEsdir-4001 CVEsdir-600l firmware1 CVEsdir-600m c1 firmware1 CVEsdir-615 t1 firmware1 CVEsdir-629-b1 CVEsdir-629-b firmware1 CVEsdir-6551 CVEsdir-655 firmware1 CVEsdir-817l\(w\) firmware1 CVEsdir-818l\(w\) firmware1 CVEsdir-823 firmware1 CVEsdir-846 firmware1 CVEsdir-850l firmare1 CVEsdir-860l firmware1 CVEsdir-866l firmware1 CVEsdir-867 firmware1 CVEs

Recent Vulnerabilities

View all 113
CVE-2022-44929CRITICAL 9.8

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

CVE-2022-44928CRITICAL 9.8

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVE-2021-33259MEDIUM 5.3

Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers to obtain users' DNS query history.

CVE-2021-41503HIGH 8.0

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-26709CRITICAL 9.8

D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated remote attackers to take over a device via the login.xgi user and pass parameters. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2019-6258CRITICAL 9.8

D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP protocol message, which is mishandled in /usr/sbin/udhcpd during reading of the /var/servd/LAN-1-udhcpd.conf file.

CVE-2020-15633HIGH 8.8

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.20B10_BETA. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP requests. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the router. Was ZDI-CAN-10835.

CVE-2020-9544HIGH 7.5

An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their choice.

CVE-2013-6811HIGH 8.8

Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding, (2) Port Triggering Entries, (3) URL Filters in Parental Control, (4) Print Server settings, (5) QoS Queue Setup, or (6) QoS Classification Entries.

CVE-2019-17663MEDIUM 6.1

D-Link DIR-866L 1.03B04 devices allow XSS via HtmlResponseMessage in the device common gateway interface, leading to common injection.

CVE-2018-19990

In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices. In the SetWiFiVerifyAlpha.php source code, the WPSPIN parameter is saved in the $rphyinf1."/media/wps/enrollee/pin" and $rphyinf2."/media/wps/enrollee/pin" and $rphyinf3."/media/wps/enrollee/pin" internal configuration memory without any regex checking. And in the do_wps function of the wps.php source code, the data in $rphyinf3."/media/wps/enrollee/pin" is used with the wpatalk command without any regex checking. A vulnerable /HNAP1/SetWiFiVerifyAlpha XML message could have shell metacharacters in the WPSPIN element such as the `telnetd` string.

CVE-2018-19989

In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth internal configuration memory without any regex checking. And in the bwc_tc_spq_start, bwc_tc_wfq_start, and bwc_tc_adb_start functions of the bwcsvcs.php source code, the data in /bwc/entry:1/bandwidth and /bwc/entry:2/bandwidth is used with the tc command without any regex checking. A vulnerable /HNAP1/SetQoSSettings XML message could have shell metacharacters in the uplink element such as the `telnetd` string.

CVE-2018-19988

In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices. In the SetClientInfoDemo.php source code, the AudioMute and AudioEnble parameters are saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. It needs to bypass the wget command option with a single quote. A vulnerable /HNAP1/SetClientInfoDemo XML message could have single quotes and backquotes in the AudioMute or AudioEnable element, such as the '`telnetd`' string.

CVE-2018-19987

D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.

CVE-2018-19986

In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices. In the SetRouterSettings.php source code, the RemotePort parameter is saved in the $path_inf_wan1."/web" internal configuration memory without any regex checking. And in the IPTWAN_build_command function of the iptwan.php source code, the data in $path_inf_wan1."/web" is used with the iptables command without any regex checking. A vulnerable /HNAP1/SetRouterSettings XML message could have shell metacharacters in the RemotePort element such as the `telnetd` string.

CVE-2018-19300

On D-Link DAP-1530 (A1) before firmware version 1.06b01, DAP-1610 (A1) before firmware version 1.06b01, DWR-111 (A1) before firmware version 1.02v02, DWR-116 (A1) before firmware version 1.06b03, DWR-512 (B1) before firmware version 2.02b01, DWR-711 (A1) through firmware version 1.11, DWR-712 (B1) before firmware version 2.04b01, DWR-921 (A1) before firmware version 1.02b01, and DWR-921 (B1) before firmware version 2.03b01, there exists an EXCU_SHELL file in the web directory. By sending a GET request with specially crafted headers to the /EXCU_SHELL URI, an attacker could execute arbitrary shell commands in the root context on the affected device. Other devices might be affected as well.

CVE-2019-9125

An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.

CVE-2019-9124

An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.

CVE-2019-7297

An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to execute arbitrary OS commands via shell metacharacters in a crafted /HNAP1 request. This occurs when the GetNetworkTomographyResult function calls the system function with an untrusted input parameter named Address. Consequently, an attacker can execute any command remotely when they control this input.

CVE-2018-20389

D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVE-2018-18767

An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.

CVE-2018-18442

D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., live-online video/audio streaming) by using the hping3 tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding, UDP flooding, ICMP flooding, and SYN-ACK flooding.

CVE-2018-18441

D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: <Camera-IP>/common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hw_version, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.

CVE-2018-20305

D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.

CVE-2018-20057

An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd allows remote authenticated users to execute arbitrary OS commands via the sysCmd POST parameter.