Exploitation timeline
Threadlinqs has recorded 9 D-Link CVEs published between and . The busiest month was 2026-02 (3 new CVEs). 2 of them (22%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 9 of 9 tracked D-Link CVEs.
- CVE-2014-8361critical 9.8KEVEPSS 100%
- CVE-2025-29635high 7.2KEVEPSS 1.3%
- CVE-2016-5681critical 9.8EPSS 11.9%
- CVE-2026-94089critical 10EPSS 1%
- CVE-2026-82592critical 9.9EPSS 0.8%
- CVE-2026-94050medium 4.3EPSS 0.2%
- CVE-2026-2129high 7.2EPSS 0.1%
- CVE-2026-2142high 7.2EPSS 0.1%
- CVE-2026-2143high 7.2EPSS 0.1%
Products affected
Threadlinqs normalises CPE and CNA product records across all 9 CVEs; 42 distinct D-Link products are affected. The most frequently affected (top 20):
- Dir-823x 4 CVEs
- Dir-823x Firmware 4 CVEs
- Dir-868l 2 CVEs
- DIR-825M 1 CVE
- DIR-X1860Z 1 CVE
- Dir-501 1 CVE
- Dir-501 Firmware 1 CVE
- Dir-515 1 CVE
- Dir-515 Firmware 1 CVE
- Dir-600l 1 CVE
- Dir-600l Firmware 1 CVE
- Dir-605l 1 CVE
- Dir-605l Firmware 1 CVE
- Dir-615 1 CVE
- Dir-615 Firmware 1 CVE
- Dir-619l 1 CVE
- Dir-619l Firmware 1 CVE
- Dir-809 1 CVE
- Dir-809 Firmware 1 CVE
- Dir-817l(w) 1 CVE
Threat activity
9 tracked threat campaigns reference D-Link products or exploit D-Link CVEs:
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394HIGH
- TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code ArtifactsMEDIUM
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit ChainHIGH
- RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector ExploitationCRITICAL
- AryStinger (Ary-Attack) Botnet Compromises 4,000+ Legacy D-Link/RTL819X Routers and NAS for Global Attack Proxy Infrastructure (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837)HIGH
- P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)HIGH
- Gafgyt Variant C0XMO — Cross-Platform IoT Botnet via DD-WRT UPnP CVE-2021-27137 with Python Lateral-Movement ModuleHIGH
- CVE-2025-29635 — Mirai Variant Campaign Recruiting D-Link DIR-823X Routers via /goform/set_prohibiting Command InjectionHIGH
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)CRITICAL
Threat actors targeting D-Link
Named threat actors attributed to campaigns that involve D-Link products or CVEs, with the number of linked campaigns:
How to prioritise D-Link patching
This order follows the data Threadlinqs holds for D-Link, not a generic severity checklist:
- 2 of 9 D-Link CVEs (22%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2014-8361, CVE-2025-29635.
- Outside KEV, the highest EPSS scores are CVE-2016-5681 (11.9%), CVE-2026-94089 (1%), CVE-2026-82592 (0.8%).
- 4 CVEs score Critical and 4 High on CVSS v3 (maximum 10, average 8.1); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.