Exploited CVEs / By vendor / D-Link

D-Link vulnerabilities actively exploited

26 D-Link CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2025-29635 (DIR-823X, added 2026-04-24). 2 of the 26 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

26 exploited CVEs2 ransomware-linked
Senserva AI Opinion and rich prompt for D-Link exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Multiple Routers: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2018-6530Multiple Routers2022-09-08ransomware, CVSS 9.8, EPSS 97%
CVE-2021-45382Multiple Routers2022-04-04CVSS 9.8, EPSS 98%
CVE-2019-16920Multiple Routers2022-03-25CVSS 9.8, EPSS 100%

Other D-Link products

CVEProductAdded to KEVSignals
CVE-2025-29635DIR-823X2026-04-24CVSS 7.2, EPSS 90%
CVE-2022-37055Routers2025-12-08CVSS 9.8, EPSS 57%
CVE-2020-25078DCS-2530L and DCS-2670L Devices2025-08-05CVSS 7.5, EPSS 98%
CVE-2020-25079DCS-2530L and DCS-2670L Devices2025-08-05CVSS 8.8, EPSS 53%
CVE-2022-40799DNR-322L2025-08-05CVSS 8.8, EPSS 32%
CVE-2024-0769DIR-859 Router2025-06-25CVSS 9.8, EPSS 83%
CVE-2023-25280DIR-820 Router2024-09-30CVSS 9.8, EPSS 98%
CVE-2014-100005DIR-600 Router2024-05-16CVSS 8.0, EPSS 42%
CVE-2021-40655DIR-605 Router2024-05-16CVSS 7.5, EPSS 87%
CVE-2024-3272Multiple NAS Devices2024-04-11CVSS 9.8, EPSS 98%
CVE-2024-3273Multiple NAS Devices2024-04-11CVSS 9.8, EPSS 100%
CVE-2016-20017DSL-2750B Devices2024-01-08CVSS 9.8, EPSS 65%
CVE-2019-17621DIR-859 Router2023-06-29CVSS 9.8, EPSS 90%
CVE-2019-20500DWL-2600AP Access Point2023-06-29CVSS 7.8, EPSS 97%
CVE-2011-4723DIR-300 Router2022-09-08CVSS 5.7, EPSS 3%
CVE-2022-26258DIR-820L2022-09-08CVSS 9.8, EPSS 80%
CVE-2019-16057DNS-320 Storage Device2022-04-15ransomware, CVSS 9.8, EPSS 87%
CVE-2013-5223DSL-2760U2022-03-25CVSS 5.4, EPSS 34%
CVE-2016-11021DCS-930L Devices2022-03-25CVSS 7.2, EPSS 69%
CVE-2020-9377DIR-610 Devices2022-03-25CVSS 8.8, EPSS 21%
CVE-2015-2051DIR-645 Router2022-02-10CVSS 8.8, EPSS 97%
CVE-2020-25506DNS-320 Device2021-11-03CVSS 9.8, EPSS 100%
CVE-2020-29557DIR-825 R1 Devices2021-11-03CVSS 9.8, EPSS 54%

Common questions about exploited D-Link CVEs

Which D-Link vulnerabilities are actively exploited?

As of August 2026, 26 D-Link CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Multiple Routers (3). 2 are linked to ransomware campaigns.

What is the newest exploited D-Link CVE?

CVE-2025-29635, affecting DIR-823X, added to the CISA KEV catalog on 2026-04-24. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these D-Link CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited D-Link CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest D-Link KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.