VendorsD-Linkdir-820lany version
Vulnerabilities

D-Link DIR-820L any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-45382
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.
Published 2022-02-17 · Analyzed
10.0KEVEPSS 0.978
CVE-2015-1187
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Published 2017-09-21 · Analyzed
10.0KEV1 PoCEPSS 0.829
CVE-2023-25280
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
Published 2023-03-16 · Analyzed
9.8KEVEPSS 0.979
CVE-2022-26258
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
Published 2022-03-27 · Analyzed
9.8KEVEPSS 0.920
CVE-2023-25279
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.
Published 2023-03-13 · Analyzed
9.8EPSS 0.310
CVE-2023-44807
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.
Published 2023-10-06 · Modified
9.8EPSS 0.011
CVE-2023-44808
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_4507CC function.
Published 2023-10-16 · Modified
9.8EPSS 0.009
CVE-2023-44809
D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
Published 2023-10-16 · Modified
9.8EPSS 0.009
CVE-2024-48150
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
Published 2024-10-14 · Analyzed
9.8EPSS 0.007
CVE-2025-52079
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
Published 2025-10-21 · Analyzed
8.8EPSS 0.005
CVE-2024-51186
D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.
Published 2024-11-11 · Analyzed
8.0EPSS 0.009