<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — D-Link</title><description>Actively exploited vulnerabilities affecting D-Link products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/d-link.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-29635 — D-Link DIR-823X Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-29635</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-29635</guid><description>The D-Link DIR-823X router contains a command injection flaw that lets an authenticated attacker run arbitrary operating system commands on the device by sending a crafted POST request to a specific configuration endpoint. Because the device is likely end-of-life or end-of-service, no patch is expected from D-Link. This gives attackers who gain even basic authenticated access full control over the router, potentially exposing the entire network behind it.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>DIR-823X</category></item><item><title>CVE-2022-37055 — D-Link Routers Buffer Overflow Vulnerability</title><link>https://wildfortech.com/security#CVE-2022-37055</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2022-37055</guid><description>This buffer overflow vulnerability in certain D-Link routers carries high impact across confidentiality, integrity, and availability — meaning an attacker could potentially read sensitive data, alter device behavior, or crash the device entirely. Making matters worse, the affected products may already be end-of-life or end-of-service, meaning D-Link may no longer issue security updates for them. Organizations still running these devices are exposed with limited options for a supported fix.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>D-Link</category><category>Routers</category></item><item><title>CVE-2020-25078 — D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability</title><link>https://wildfortech.com/security#CVE-2020-25078</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2020-25078</guid><description>This vulnerability in D-Link DCS-2530L and DCS-2670L IP cameras allows remote attackers to obtain the administrator password without authentication. Since these are network-connected cameras, exploitation could give an attacker full administrative control, enabling surveillance feed access, device reconfiguration, or use of the camera as a foothold for further network attacks. The risk is compounded by the fact that these products are likely end-of-life, meaning D-Link may no longer provide ongoing security support.</description><pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate><category>D-Link</category><category>DCS-2530L and DCS-2670L Devices</category></item><item><title>CVE-2020-25079 — D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2020-25079</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2020-25079</guid><description>This vulnerability allows attackers to inject arbitrary operating system commands through the cgi-bin/ddns_enc.cgi interface on D-Link DCS-2530L and DCS-2670L IP cameras. Successful exploitation could give an attacker control over the device, potentially enabling surveillance access, network pivoting, or use in botnets. These devices are likely end-of-life or end-of-service, meaning ongoing vendor security support may no longer exist, making any deployment a persistent risk.</description><pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate><category>D-Link</category><category>DCS-2530L and DCS-2670L Devices</category></item><item><title>CVE-2022-40799 — D-Link DNR-322L Download of Code Without Integrity Check Vulnerability</title><link>https://wildfortech.com/security#CVE-2022-40799</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2022-40799</guid><description>The D-Link DNR-322L network video recorder contains a flaw where firmware or code can be downloaded and executed without verifying its integrity. An authenticated attacker can exploit this to run arbitrary OS-level commands on the device, effectively taking full control. Because this product is likely end-of-life or end-of-service, D-Link is not expected to release a patch, leaving any deployed unit permanently exposed to this serious command execution risk.</description><pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate><category>D-Link</category><category>DNR-322L</category></item><item><title>CVE-2024-0769 —  D-Link DIR-859 Router Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-0769</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-0769</guid><description>D-Link DIR-859 routers have a path traversal flaw in the hedwig.cgi handler that lets an attacker manipulate HTTP POST requests to read sensitive session data from the device. With that session information, an attacker could escalate privileges and take full unauthorized control of the router. Critically, D-Link has declared all hardware revisions of this product end-of-life or end-of-service, meaning no security patches will be issued, leaving any deployed unit permanently exposed.</description><pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate><category>D-Link</category><category>DIR-859 Router</category></item></channel></rss>