D-Link vendor intelligence
D-Link Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting D-Link products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 53
- Known exploited vulnerabilities affecting D-Link products
- In CISA KEV
- 27
- Records also listed in the official catalog
- Beyond CISA KEV
- 26
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 3
- D-Link KEVs with sensor-observed exploitation activity
The catalog gap matters for D-Link exposure
26 of the 53 exploited D-Link vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 49% of this vendor portfolio.
- 51%
- Covered by CISA
- 49%
- Beyond CISA
- 48
- Product families
Attested D-Link vulnerabilities
53 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635... |
DCS-3411/3430, DCS-5605/5635, DCS-1100L/1130L, DCS-1100/1130, DCS-2102/2121, DCS-3410, DCS-5230, DCS-6410, DCS-7410, DCS-7510, WCS-1100 | High | Beyond CISA | 28 Jan 2020 |
|
CVE-2018-15517
The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually... |
Central WiFiManager CWM-100 | High | Beyond CISA | 31 Jan 2019 |
|
CVE-2018-10823
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and... |
DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, DWR-111 | High | Beyond CISA | 17 Oct 2018 |
No D-Link vulnerabilities match this search or filter.
Showing 3 of 3 on this page (53 D-Link known exploited vulnerabilities).
Recurring weakness patterns
Neutralization, neutralization, and missing authentication for critical function account for 35 mapped occurrences across this D-Link KEV portfolio.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-306
Missing Authentication for Critical Function
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-798
Use of Hard-coded Credentials
CWE-287
Improper Authentication
CWE-312
Cleartext Storage of Sensitive Information