The U.S. Cybersecurity and Infrastructure Security Administration (CISA) has issued a new warning, adding three vulnerabilities affecting D-Link devices to the List of Known Exploitable Vulnerabilities (KEV).
See also: Critical D-Link flaw leads to server crash

The inclusion of these vulnerabilities on the list means that they are actively exploited by malicious actors in real-world attacks, posing a significant threat to networks.
The three vulnerabilities affect several D-Link products and are now subject to a federal agency mandate to address them. The specific vulnerabilities are:
– **CVE-2020-25078**: An unspecified vulnerability affecting D-Link DCS-2530L and DCS-2670L.
– **CVE-2020-25079**: A command injection vulnerability also affecting D-Link DCS-2530L and DCS-2670L.
– **CVE-2022-40799**: A vulnerability allowing code execution without integrity check in the D-Link DNR-322L.
These types of security vulnerabilities are common entry points for attackers. Command execution vulnerabilities can allow an attacker to execute arbitrary commands on the operating system , potentially leading to a complete takeover.
See also: Vulnerability in D-Link Routers allows complete control of the router
Similarly, the ability to download and execute code without verifying its integrity opens the door for the installation of malware, turning the compromised device into a tool for broader network penetration or a node in a botnet.

The addition of these CVEs to the KEV List falls under the Binding Operational Direction (BOD) 22-01, which mandates federal agencies of the Federal Criminal Enforcement Bureau (FCEB) to remediate the identified vulnerabilities by a set deadline.
The direction defined the KEV List as a dynamic list of known CVEs that present a significant risk to the federal enterprise. The goal is to ensure that federal networks are protected from active and ongoing threats.
While BOD 22-01 is only mandatory for FCEB services , CISA has strongly encouraged all organizations, public and private, to take this warning seriously. The agency recommends that all entities reduce their exposure to cyberattacks by prioritizing timely remediation of vulnerabilities listed in the KEV List as a core part of their vulnerability management practices .
See also: Malware botnets exploit outdated D-Link routers
CISA continually updates the list as new evidence of active exploitation, based on a set of defined criteria. Device owners are encouraged to check for firmware updates from the manufacturer and apply them promptly to mitigate these threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
