D-Link threat watch

D-Link CVE coverage for routers, cameras, NAS devices, and end-of-life edge equipment still present in business networks.

Watch items

Recent D-Link watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows ยท sorted newest first

Operations view

D-Link DNS-320 vulnerability (CVE-2026-16447)

MEDIUM
watchNVDCVE-2026-16447

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

Jul 21, 2026, 9:16 AMOfficial source

D-Link DNS-320 vulnerability (CVE-2026-16332)

MEDIUM
watchNVDCVE-2026-16332

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Jul 20, 2026, 10:16 PMOfficial source

D-Link DNS-320 vulnerability (CVE-2026-16331)

MEDIUM
watchNVDCVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Jul 20, 2026, 8:16 PMOfficial source

D-Link DNS-320 vulnerability (CVE-2026-16330)

MEDIUM
watchNVDCVE-2026-16330

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

Jul 20, 2026, 8:16 PMOfficial source

D-Link DNS-320 vulnerability (CVE-2026-16329)

MEDIUM
watchNVDCVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.

Jul 20, 2026, 8:16 PMOfficial source

D-Link DNS-320 vulnerability (CVE-2026-16327)

MEDIUM
watchNVDCVE-2026-16327

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Jul 20, 2026, 7:16 PMOfficial source

D-Link DIR-823G vulnerability (CVE-2026-15270)

MEDIUM
watchNVDCVE-2026-15270

A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.

Jul 9, 2026, 3:16 PMOfficial source

dcs-935l firmware vulnerability (CVE-2026-12174)

HIGH
watchNVDCVE-2026-12174

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Jun 13, 2026, 4:16 PMOfficial source

dgs-1100-08pd firmware vulnerability (CVE-2026-11555)

LOW
watchNVDCVE-2026-11555

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

Jun 8, 2026, 1:16 PMOfficial source

dcs-5615 firmware vulnerability (CVE-2026-11497)

MEDIUM
watchNVDCVE-2026-11497

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Jun 8, 2026, 4:16 AMOfficial source

dir-823g firmware vulnerability (CVE-2026-11492)

LOW
watchNVDCVE-2026-11492

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Jun 8, 2026, 2:16 AMOfficial source

dwr-m920 firmware vulnerability (CVE-2026-11339)

LOW
watchNVDCVE-2026-11339

A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Jun 5, 2026, 12:16 PMOfficial source

dwr-m920 firmware vulnerability (CVE-2026-10878)

LOW
watchNVDCVE-2026-10878

A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Jun 4, 2026, 7:16 PMOfficial source

di-7001mini-8g firmware vulnerability (CVE-2026-10270)

HIGH
watchNVDCVE-2026-10270

A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

Jun 1, 2026, 12:16 PMOfficial source

D-Link DI-8400 vulnerability (CVE-2026-10206)

HIGH
watchNVDCVE-2026-10206

A vulnerability was detected in D-Link DI-8400 up to 16.07.26A1. This affects an unknown function of the file /dbsrv.asp. Performing a manipulation of the argument str results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The initial researcher advisory mentions contradicting parameter names to be affected.

May 31, 2026, 8:16 PMOfficial source

dir-816 firmware vulnerability (CVE-2026-8346)

LOW
watchNVDCVE-2026-8346

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.

May 11, 2026, 7:17 PMOfficial source

dir-816 firmware vulnerability (CVE-2026-8345)

LOW
watchNVDCVE-2026-8345

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

May 11, 2026, 6:20 PMOfficial source

dir-816 firmware vulnerability (CVE-2026-8344)

LOW
watchNVDCVE-2026-8344

A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

May 11, 2026, 5:22 PMOfficial source

dns-320 firmware vulnerability (CVE-2026-8273)

MEDIUM
watchNVDCVE-2026-8273

A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely.

May 11, 2026, 12:16 AMOfficial source

dns-320 firmware vulnerability (CVE-2026-8272)

LOW
watchNVDCVE-2026-8272

A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

May 11, 2026, 12:16 AMOfficial source

Vendor watch hub

What this page covers

The D-Linkwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent D-Link activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

238

Active

28

Featured

58

Unique CVEs

20

Most recent entry

Jul 21, 2026, 9:16 AM

Feed refreshes daily ยท 5:15 a.m. Central

SourcesยทCISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published โ€” not our sync time.

Related vendors

Other security vendors in the radar

Vendor watch FAQ

Common questions

What is the D-Link threat watch page?

It is the D-Link-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the D-Link watch page?

Use it to confirm whether current D-Link issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to D-Link security issues?

Yes. ITECS can help map D-Link advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.