Skip to content
ThreatCluster

Remote Code Execution Vulnerabilities in D-Link Devices

First seen 11 Oct 2026, 10:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC
  • •CVE-2022-26258 and CVE-2019-16057 are critical vulnerabilities in D-Link devices.
  • •Both vulnerabilities allow remote code execution with a CVSS score of 9.8.
  • •CISA confirmed active exploitation and remediation deadlines have passed.

Two vulnerabilities have been identified in D-Link devices, CVE-2022-26258 and CVE-2019-16057, both allowing remote code execution. CVE-2022-26258 affects the D-Link DIR-820L router, while CVE-2019-16057 impacts the D-Link DNS-320 storage device. Both vulnerabilities have a CVSS score of 9.8, categorizing them as. CISA confirmed exploitation in the wild for both vulnerabilities, with CVE-2022-26258 added to the KEV catalog on September 8, 2022, and CVE-2019-16057 on April 15, 2022. The CISA remediation deadlines for both vulnerabilities have long passed, raising concerns about devices. Affected organizations include US federal civilian agencies and other users of these D-Link products. The vulnerabilities stem from issues in the device's web management interfaces, allowing attackers to execute arbitrary code remotely. Users are urged to apply patches and secure their devices against potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-09-16
CVE-2019-16057 published
D-Link DNS-320 vulnerability disclosed, allowing remote code execution.
Netvigilance
2022-03-27
CVE-2022-26258 published
D-Link DIR-820L vulnerability disclosed, allowing remote code execution.
Netvigilance
2022-04-15
CVE-2019-16057 added to CISA KEV
CISA confirmed active exploitation of the vulnerability in the wild.
Netvigilance
2022-09-08
CVE-2022-26258 added to CISA KEV
CISA confirmed active exploitation of the vulnerability in the wild.
Netvigilance

More articles in this cluster (4)

Following this threat?

Track CVE-2019-16057 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which D-Link devices are affected?
The D-Link DIR-820L router and the D-Link DNS-320 storage device are affected.
What is the CVSS score for these vulnerabilities?
Both CVE-2022-26258 and CVE-2019-16057 have a CVSS score of 9.8, indicating critical severity.
What actions should be taken to mitigate these vulnerabilities?
Users should apply available patches immediately and secure their devices to prevent exploitation.