<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — D-Link</title><description>Coverage of CVEs, patches, and active exploitation affecting D-Link networking hardware including SOHO routers, 4G LTE gateways, and access points. D-Link devices are widely deployed in home and small business networks, and firmware vulnerabilities in the DWR, DSL, and DIR series recur across successive models. Combined article + CVE feed for the D-Link beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>D-Link DWR Routers Hit by Three Critical Command Injections</title><link>https://0daynews.com/articles/2026-09-16-d-link-dwr-m921-m920-command-injection-three-cves/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-16-d-link-dwr-m921-m920-command-injection-three-cves/</guid><description>Three critical command injection flaws in D-Link DWR-M920 and DWR-M921 firmware. Researcher H3rmesk1t disclosed all three; no D-Link patch available.</description><pubDate>Wed, 16 Sep 2026 16:00:00 GMT</pubDate><category>D-Link</category><category>article</category></item><item><title>CVE-2011-4723 — D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability</title><link>https://0daynews.com/cve/cve-2011-4723/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2011-4723/</guid><description>The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>medium</category><category>cve</category></item><item><title>CVE-2013-5223 — D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability</title><link>https://0daynews.com/cve/cve-2013-5223/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2013-5223/</guid><description>A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>medium</category><category>cve</category></item><item><title>CVE-2014-100005 — D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2014-100005/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-100005/</guid><description>D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2015-2051 — D-Link DIR-645 Router Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2015-2051/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-2051/</guid><description>D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2016-11021 — D-Link DCS-930L Devices OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2016-11021/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-11021/</guid><description>setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2016-20017 — D-Link DSL-2750B Devices Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2016-20017/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-20017/</guid><description>D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2018-6530 — D-Link Multiple Routers OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2018-6530/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-6530/</guid><description>Multiple D-Link routers contain an unspecified vulnerability that allows for execution of OS commands.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-16057 — D-Link DNS-320 Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-16057/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-16057/</guid><description>The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-16920 — D-Link Multiple Routers Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2019-16920/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-16920/</guid><description>Multiple D-Link routers contain a command injection vulnerability which can allow attackers to achieve full system compromise.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-17621 — D-Link DIR-859 Router Command Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-17621/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-17621/</guid><description>D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote attacker to execute system commands as root by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-20500 — D-Link DWL-2600AP Access Point Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2019-20500/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-20500/</guid><description>D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2020-25078 — D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability</title><link>https://0daynews.com/cve/cve-2020-25078/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-25078/</guid><description>D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2020-25079 — D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2020-25079/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-25079/</guid><description>D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2020-25506 — D-Link DNS-320 Device Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2020-25506/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-25506/</guid><description>D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-29557 — D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2020-29557/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-29557/</guid><description>D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-9377 — D-Link DIR-610 Devices Remote Command Execution</title><link>https://0daynews.com/cve/cve-2020-9377/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-9377/</guid><description>D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2021-40655 — D-Link DIR-605 Router Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2021-40655/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-40655/</guid><description>D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. </description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2021-45382 — D-Link Multiple Routers Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2021-45382/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-45382/</guid><description>A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-26258 — D-Link DIR-820L Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26258/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26258/</guid><description>D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote code execution.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-37055 — D-Link Routers Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2022-37055/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-37055/</guid><description>D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-40799 — D-Link DNR-322L Download of Code Without Integrity Check Vulnerability</title><link>https://0daynews.com/cve/cve-2022-40799/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-40799/</guid><description>D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2023-25280 — D-Link DIR-820 Router OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-25280/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-25280/</guid><description>D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-0769 —  D-Link DIR-859 Router Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-0769/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-0769/</guid><description>D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-3272 — D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability</title><link>https://0daynews.com/cve/cve-2024-3272/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-3272/</guid><description>D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-3273 — D-Link Multiple NAS Devices Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-3273/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-3273/</guid><description>D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2025-29635 — D-Link DIR-823X Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2025-29635/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-29635/</guid><description>D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>high</category><category>cve</category></item><item><title>CVE-2026-90699 — D-Link DWR-M920 command injection via SIM PIN management endpoint</title><link>https://0daynews.com/cve/cve-2026-90699/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-90699/</guid><description>D-Link DWR-M920 firmware 1.1.7 passes the newPin argument from /boafrm/formPinManageSetup directly to the system shell, allowing OS command injection. CVSS 9.9 critical.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-90702 — D-Link DWR-M921 command injection via disk format endpoint</title><link>https://0daynews.com/cve/cve-2026-90702/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-90702/</guid><description>D-Link DWR-M921 firmware 1.1.52 passes the partition argument from /boafrm/formDiskFormat to the system shell without sanitization, enabling OS command injection. CVSS 9.1 critical.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-90703 — D-Link DWR-M921 command injection via disk share creation endpoint</title><link>https://0daynews.com/cve/cve-2026-90703/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-90703/</guid><description>D-Link DWR-M921 firmware 1.1.52 passes the folderpath argument from /boafrm/formDiskCreateShare to the system shell without sanitization, enabling OS command injection. CVSS 9.1 critical.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>D-Link</category><category>critical</category><category>cve</category></item></channel></rss>