D-Link vulnerabilities
23 CVEs tracked
D-Link appears in our reporting within two main contexts: analysis of a Russian-speaking operator's toolkit targeting Ukrainian IP cameras and the discovery of critical vulnerabilities in D-Link DWR-M961 devices. The primary focus is on multiple command injection vulnerabilities (CVE-2026-71944, CVE-2026-71945, CVE-2026-71946, CVE-2026-71947, CVE-2026-71948, CVE-2026-71949, CVE-2026-71951) found in the hardware version C1 of the DWR-M961 model, allowing remote attackers to execute commands via parameters like 'fota_url', 'host', or 'IMEI_value'. Additionally, an older report mentions CVE-2026-19893 for the DIR-842 model. As a defender, immediate firmware updates (to version 1.1.5_C1 or later) should be a priority, especially for internet-exposed D-Link DWR-M961 devices.
Azərbaycanca: D-Link hesabatlarımızda iki əsas kontekstdə görünür: Ukraynadakı IP kameraları hədəf alan Rusdilli operatorun alət dəsti ilə bağlı təhlil və D-Link DWR-M961 cihazlarında aşkarlanmış kritik zəifliklər. Əsas diqqət nöqtəsi DWR-M961 modelinin hardware C1 versiyasında tapılan çoxsaylı command injection zəiflikləridir (CVE-2026-71944, CVE-2026-71945, CVE-2026-71946, CVE-2026-71947, CVE-2026-71948, CVE-2026-71949, CVE-2026-71951), hansı ki, uzaqdan hücum edənə “fota_url”, “host”, “IMEI_value” kimi parametrlər vasitəsilə əmr icra etməyə imkan verir. Bundan əlavə, köhnə hesabatda DIR-842 modeli üçün CVE-2026-19893 zəifliyi qeyd olunur. Müdafiəçi kimi, xüsusilə internetə açıq olan D-Link DWR-M961 cihazları üçün dərhal firmware yeniləməsi (1.1.5_C1 və ya daha yuxarı versiyaya) prioritet olmalıdır.
This vendor's CVEs23
- CVE-2021-36260KEVEPSS 100%
- CVE-2021-33044KEVEPSS 100%
- CVE-2020-25078KEVEPSS 98%
- CVE-2017-7921KEVEPSS 100%
- CVE-2026-71958EPSS 0.56%
- CVE-2026-71957EPSS 0.59%
- CVE-2026-71956EPSS 2%
- CVE-2026-71955EPSS 2%
- CVE-2026-71954EPSS 2%
- CVE-2026-71953EPSS 2%
- CVE-2026-71952EPSS 2%
- CVE-2026-71951EPSS 2%
- CVE-2026-71950EPSS 2%
- CVE-2026-71949EPSS 2%
- CVE-2026-71948EPSS 2%
- CVE-2026-71947EPSS 2%
- CVE-2026-71946EPSS 2%
- CVE-2026-71945EPSS 2%
- CVE-2026-71944EPSS 2%
- CVE-2026-19893EPSS 0.29%
- CVE-2024-57049
- CVE-2024-53375EPSS 41%
- CVE-2020-25169EPSS 0.99%
This hub is built from skopnix's own reporting on D-Link: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.