By vendor
Dlink vulnerabilities
Known CVEs affecting Dlink products, prioritized by severity, with SEC.co remediation and detection guidance.
9 published vulnerabilities
- CVE-2026-10270HIGH 8.8
D-Link DI-7001 MINI routers running firmware version 19.09.19A1 and earlier contain a stack-based buffer overflow in the web API debug interface. An attacker with valid login credentials can send a specially crafted request to the /httpd_debug.asp endpoint that overflows a buffer, potentially allowing arbitrary code execution on the device. Exploit code has been publicly disclosed, elevating near-term risk.
- CVE-2026-12174HIGH 8.8
D-Link DCS-935L cameras running firmware version 1.10.01 contain a format string vulnerability in their web interface. An attacker with valid login credentials can send specially crafted requests to a specific CGI handler to read sensitive memory, modify system behavior, or execute code on the device. The vulnerability requires authentication but offers no other barriers; it can be exploited over the network without user interaction.
- CVE-2026-13545HIGH 8.8
D-Link DCS-935L network cameras running firmware version 1.10.01 contain a critical flaw in their web configuration interface. An authenticated attacker can inject arbitrary operating system commands through the UID parameter in the setconf.cgi handler, gaining the ability to execute code with the privileges of the camera process. Because the vulnerability requires authentication but offers full system compromise once inside, it represents a high-severity risk for organizations relying on these devices for surveillance infrastructure.
- CVE-2026-15270HIGH 7.5
A privilege escalation vulnerability has been discovered in D-Link DIR-823G routers running firmware version 1.0.2B05_20181207. An authenticated attacker can manipulate the web interface configuration files to bypass access controls and gain unauthorized elevated privileges on the device. While exploitation requires legitimate login credentials and involves complex technical steps, public proof-of-concept code now exists, increasing the practical risk to deployed devices.
- CVE-2026-10878MEDIUM 6.3
A command injection vulnerability has been discovered in D-Link DWR-M920 routers running firmware versions 1.1.50 and 1.1.70. An authenticated attacker can manipulate a parameter in the SMS management interface to inject and execute arbitrary system commands. This requires an existing login to the device but does not require user interaction once authenticated. Public exploits are now available, increasing the practical risk.
- CVE-2026-11339MEDIUM 6.3
A command injection vulnerability exists in D-Link DWR-M920 routers up to firmware version 1.1.50. An authenticated attacker can inject arbitrary commands through the USSD Setup function, potentially gaining remote code execution on the device. The vulnerability requires valid login credentials but does not need user interaction to exploit. Public exploit code is now available.
- CVE-2026-11497MEDIUM 5.3
A vulnerability exists in D-Link DCS-5615 network camera firmware version 1.01.00 affecting the Boa web server configuration. An unauthenticated remote attacker can manipulate the web server settings to escalate privileges or modify system functionality without proper authorization. The vulnerability requires no special interaction from the user and can be exploited over the network. While the technical impact is bounded to integrity violations, the ability to alter web server configuration on a networked device introduces operational risk, particularly in environments where the camera serves as a network endpoint with security implications.
- CVE-2026-11492MEDIUM 4.3
A vulnerability in the D-Link DIR-823G router (firmware version 1.0.2B05) allows an authenticated attacker to modify the vsftpd configuration file in a way that violates least privilege protections. The flaw can be exploited remotely by someone with valid login credentials. While the barrier to entry requires authentication, the impact is a privilege escalation that could allow an attacker to exceed their intended access level on the device.
- CVE-2026-11555LOW 3.7
A privilege escalation vulnerability exists in D-Link's DGS-1100-08PD switch running firmware version 1.00.006. The issue resides in how the web interface processes the /etc/boa.conf configuration file, potentially allowing an attacker to modify system settings in ways that bypass normal access restrictions. While a public exploit exists, successful exploitation requires significant technical skill and specific conditions to align. The impact is limited to integrity violations—an attacker cannot read sensitive data or crash the device, only make unauthorized configuration changes.