# D-Link vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 9 D-Link CVEs, 2 in the CISA Known Exploited Vulnerabilities catalog, linked to 9 tracked threat campaigns and 6 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 9 D-Link CVEs published between 2015-05-15 and 2026-09-15. The busiest month was 2026-02 (3 new CVEs). 2 of them (22%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 9 of 9 tracked D-Link CVEs.

- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361) — CRITICAL 9.8 · KEV · EPSS 100% · 2015-05-01
- [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635) — HIGH 7.2 · KEV · EPSS 1.3% · 2025-03-25
- [CVE-2016-5681](https://intel.threadlinqs.com/cve/CVE-2016-5681) — CRITICAL 9.8 · EPSS 11.9% · 2016-08-25
- [CVE-2026-94089](https://intel.threadlinqs.com/cve/CVE-2026-94089) — CRITICAL 10 · EPSS 1% · 2026-09-20
- [CVE-2026-82592](https://intel.threadlinqs.com/cve/CVE-2026-82592) — CRITICAL 9.9 · EPSS 0.8% · 2026-08-30
- [CVE-2026-94050](https://intel.threadlinqs.com/cve/CVE-2026-94050) — MEDIUM 4.3 · EPSS 0.2% · 2026-09-20
- [CVE-2026-2129](https://intel.threadlinqs.com/cve/CVE-2026-2129) — HIGH 7.2 · EPSS 0.1% · 2026-02-08
- [CVE-2026-2142](https://intel.threadlinqs.com/cve/CVE-2026-2142) — HIGH 7.2 · EPSS 0.1% · 2026-02-08
- [CVE-2026-2143](https://intel.threadlinqs.com/cve/CVE-2026-2143) — HIGH 7.2 · EPSS 0.1% · 2026-02-08

## Products affected

Threadlinqs normalises CPE and CNA product records across all 9 CVEs; 42 distinct D-Link products are affected. The most frequently affected (top 20):

- Dir-823x — 4 CVEs
- Dir-823x Firmware — 4 CVEs
- Dir-868l — 2 CVEs
- DIR-825M — 1 CVE
- DIR-X1860Z — 1 CVE
- Dir-501 — 1 CVE
- Dir-501 Firmware — 1 CVE
- Dir-515 — 1 CVE
- Dir-515 Firmware — 1 CVE
- Dir-600l — 1 CVE
- Dir-600l Firmware — 1 CVE
- Dir-605l — 1 CVE
- Dir-605l Firmware — 1 CVE
- Dir-615 — 1 CVE
- Dir-615 Firmware — 1 CVE
- Dir-619l — 1 CVE
- Dir-619l Firmware — 1 CVE
- Dir-809 — 1 CVE
- Dir-809 Firmware — 1 CVE
- Dir-817l(w) — 1 CVE

## Threat activity

9 tracked threat campaigns reference D-Link products or exploit D-Link CVEs:

- [Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394](https://intel.threadlinqs.com/threat/TL-2026-2857) — HIGH — 2026-10-03
- [TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts](https://intel.threadlinqs.com/threat/TL-2026-1397) — MEDIUM — 2026-07-16
- [TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain](https://intel.threadlinqs.com/threat/TL-2026-1366) — HIGH — 2026-07-15
- [RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1006) — CRITICAL — 2026-06-30
- [AryStinger (Ary-Attack) Botnet Compromises 4,000+ Legacy D-Link/RTL819X Routers and NAS for Global Attack Proxy Infrastructure (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837)](https://intel.threadlinqs.com/threat/TL-2026-0894) — HIGH — 2026-06-21
- [P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)](https://intel.threadlinqs.com/threat/TL-2026-0752) — HIGH — 2026-06-10
- [Gafgyt Variant C0XMO — Cross-Platform IoT Botnet via DD-WRT UPnP CVE-2021-27137 with Python Lateral-Movement Module](https://intel.threadlinqs.com/threat/TL-2026-0679) — HIGH — 2026-06-04
- [CVE-2025-29635 — Mirai Variant Campaign Recruiting D-Link DIR-823X Routers via /goform/set_prohibiting Command Injection](https://intel.threadlinqs.com/threat/TL-2026-0406) — HIGH — 2026-04-21
- [Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)](https://intel.threadlinqs.com/threat/TL-2026-0183) — CRITICAL — 2026-03-06

## Threat actors targeting D-Link

Named threat actors attributed to campaigns that involve D-Link products or CVEs, with the number of linked campaigns:

- [APT33](https://intel.threadlinqs.com/actor/APT33) — 1 campaign
- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1 campaign
- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers) — 1 campaign
- [Handala Hack Team](https://intel.threadlinqs.com/actor/Handala%20Hack%20Team) — 1 campaign
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 1 campaign

## How to prioritise D-Link patching

This order follows the data Threadlinqs holds for D-Link, not a generic severity checklist:

- 2 of 9 D-Link CVEs (22%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361), [CVE-2025-29635](https://intel.threadlinqs.com/cve/CVE-2025-29635).
- Outside KEV, the highest EPSS scores are [CVE-2016-5681](https://intel.threadlinqs.com/cve/CVE-2016-5681) (11.9%), [CVE-2026-94089](https://intel.threadlinqs.com/cve/CVE-2026-94089) (1%), [CVE-2026-82592](https://intel.threadlinqs.com/cve/CVE-2026-82592) (0.8%).
- 4 CVEs score Critical and 4 High on CVSS v3 (maximum 10, average 8.1); sequence these after KEV and high-EPSS items.
- 3 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/d-link
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
