D-Link vendor intelligence

D-Link Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting D-Link products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEVs Full KEV feed
Total KEVs
53
Known exploited vulnerabilities affecting D-Link products
In CISA KEV
27
Records also listed in the official catalog
Beyond CISA KEV
26
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
3
D-Link KEVs with sensor-observed exploitation activity

The catalog gap matters for D-Link exposure

26 of the 53 exploited D-Link vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 49% of this vendor portfolio.

51%
Covered by CISA
49%
Beyond CISA
48
Product families

Attested D-Link vulnerabilities

53 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2013-1599

A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635...

DCS-3411/3430, DCS-5605/5635, DCS-1100L/1130L, DCS-1100/1130, DCS-2102/2121, DCS-3410, DCS-5230, DCS-6410, DCS-7410, DCS-7510, WCS-1100 High Beyond CISA 28 Jan 2020
CVE-2018-15517

The MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but actually...

Central WiFiManager CWM-100 High Beyond CISA 31 Jan 2019
CVE-2018-10823

An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and...

DWR-116, DWR-512, DWR-712, DWR-912, DWR-921, DWR-111 High Beyond CISA 17 Oct 2018

Showing 3 of 3 on this page (53 D-Link known exploited vulnerabilities).

Recurring weakness patterns

Neutralization, neutralization, and missing authentication for critical function account for 35 mapped occurrences across this D-Link KEV portfolio.

Browse all KEVs →