« Back to list

Dlink

Dlink Dir-615 Firmware: vulnerabilities and CVEs

Dlink Dir-615 Firmware has 19 published vulnerabilities, 5 of them in the last 12 months. 6 are rated critical and 2 are listed by CISA as actively exploited.

CVEs19
Last 12 months5
Critical6
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2014-8361Critical (9.8)100%⚠ Active exploitationMay 1, 2015
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
CVE-2019-16920Critical (9.8)100%⚠ Active exploitationSep 27, 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-2152High (7.3)4.8%—Feb 8, 2026
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of the component Web Configuration Interface. Performing a manipulation of the argument dest_ip/…
CVE-2026-2151High (7.3)4.7%—Feb 8, 2026
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr leads to os command…
CVE-2026-1506High (7.3)5.6%—Jan 28, 2026
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command…
CVE-2026-1505High (7.3)5.1%—Jan 28, 2026
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes.php of the component URL Filter. The manipulation results in os command injection. The attack can…
CVE-2026-1448High (7.3)5.8%—Jan 27, 2026
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument…
CVE-2018-25115Critical (10)10%—Aug 27, 2025
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to…
CVE-2013-10050High (8.7)14%—Aug 1, 2025
An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly…
CVE-2024-0717Medium (5.3)18%—Jan 19, 2024
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825,…
CVE-2021-42627Critical (9.8)63%—Aug 23, 2022
The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker…
CVE-2021-40654Medium (6.5)1.9%—Sep 24, 2021
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
CVE-2021-37388Critical (9.8)3.7%—Aug 6, 2021
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.
CVE-2019-17525High (8.8)5.8%—Apr 21, 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.
CVE-2019-19742Medium (4.8)20%—Dec 18, 2019
On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field.
CVE-2019-17353High (8.2)3.0%—Oct 9, 2019
An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be…
CVE-2019-16920Critical (9.8)100%⚠ Active exploitationSep 27, 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway…
CVE-2018-15839Critical (9.8)45%—Aug 28, 2018
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
CVE-2018-15875Medium (6.1)1.2%—Aug 25, 2018
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows attackers to inject JavaScript into the router's admin UPnP page via the description field in an AddPortMapping UPnP SOAP request.
CVE-2018-15874Medium (6.1)1.2%—Aug 25, 2018
Cross-site scripting (XSS) vulnerability on D-Link DIR-615 routers 20.07 allows an attacker to inject JavaScript into the "Status -> Active Client Table" page via the hostname field in a DHCP request.
CVE-2014-8361Critical (9.8)100%⚠ Active exploitationMay 1, 2015
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1059 Command and Scripting Interpreter1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Dlink