cbcvebase.

Dlink Dir-816 Firmware vulnerabilities

73 known vulnerabilities affecting dlink/dir-816_firmware.

Total CVEs
73
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL42HIGH13MEDIUM18

Vulnerabilities

Page 1 of 4
CVE-2022-37129P1HIGHCVSS 8.8Exploitedv1.10cnb042022-08-31
CVE-2022-37129 [HIGH] CWE-78 CVE-2022-37129: D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.
nvd
CVE-2021-39509P1CRITICALCVSS 9.8Exploitedv1.10cnb05_r1b011d882102021-08-24
CVE-2021-39509 [CRITICAL] CWE-77 CVE-2021-39509: An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request param An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
nvd
CVE-2022-37130P2CRITICALCVSS 9.8v1.10cnb042022-08-31
CVE-2022-37130 [CRITICAL] CWE-78 CVE-2022-37130: In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occ In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability
nvd
CVE-2025-5623P2CRITICALCVSS 9.8v1.10cnb052025-06-05
CVE-2025-5623 [CRITICAL] CWE-119 CVE-2025-5623: A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affe A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the publ
nvd
CVE-2024-57684P2CRITICALCVSS 9.8v1.10cnb05_r1b011d882102025-01-16
CVE-2024-57684 [CRITICAL] CWE-276 CVE-2024-57684: An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allow An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
nvd
CVE-2025-5621P2CRITICALCVSS 9.8v1.10cnb052025-06-05
CVE-2025-5621 [CRITICAL] CWE-77 CVE-2025-5621: A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by t A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public
nvd
CVE-2025-5620P2CRITICALCVSS 9.8v1.10cnb052025-06-05
CVE-2025-5620 [CRITICAL] CWE-77 CVE-2025-5620: A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected i A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2022-37128P2CRITICALCVSS 9.8v1.10cnb042022-08-31
CVE-2022-37128 [CRITICAL] CWE-665 CVE-2022-37128: In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /gofor In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
nvd
CVE-2026-4183P2CRITICALCVSS 9.8v1.10cnb052026-03-16
CVE-2026-4183 [CRITICAL] CWE-119 CVE-2026-4183: A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown funct A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Th
nvd
CVE-2026-8344P2HIGHCVSS 8.8v1.10cnb05_r1b011d882102026-05-11
CVE-2026-8344 [HIGH] CWE-74 CVE-2026-8344: A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerabil A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2022-37134P2CRITICALCVSS 9.8v1.10cnb042022-08-22
CVE-2022-37134 [CRITICAL] CWE-1284 CVE-2022-37134: D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wan D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.
nvd
CVE-2025-5624P2CRITICALCVSS 9.8v1.10cnb052025-06-05
CVE-2025-5624 [CRITICAL] CWE-119 CVE-2025-5624: A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulner A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument port0_group/port0_remarker/ssid0_group/ssid0_remarker leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit
nvd
CVE-2026-8345P2HIGHCVSS 8.8v1.10cnb05_r1b011d882102026-05-11
CVE-2026-8345 [HIGH] CWE-74 CVE-2026-8345: A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by thi A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-8346P2HIGHCVSS 8.8v1.10cnb05_r1b011d882102026-05-12
CVE-2026-8346 [HIGH] CWE-74 CVE-2026-8346: A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function por A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.
nvd
CVE-2021-27114P2CRITICALCVSS 9.8v1.10b052021-04-14
CVE-2021-27114 [CRITICAL] CWE-787 CVE-2021-27114: An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /g An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.
nvd
CVE-2022-29322P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29322 [CRITICAL] CWE-787 CVE-2022-29322: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.
nvd
CVE-2023-24331P2CRITICALCVSS 9.8v1.10nb042024-02-21
CVE-2023-24331 [CRITICAL] CWE-77 CVE-2023-24331: Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.
nvd
CVE-2025-5630P2CRITICALCVSS 9.8v1.10cnb052025-06-05
CVE-2025-5630 [CRITICAL] CWE-119 CVE-2025-5630: A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerab A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulner
nvd
CVE-2025-5622P2CRITICALCVSS 9.8v1.10cnb052025-06-05
CVE-2025-5622 [CRITICAL] CWE-119 CVE-2025-5622: A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this i A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has bee
nvd
CVE-2026-4184P2CRITICALCVSS 9.8v1.10cnb052026-03-16
CVE-2026-4184 [CRITICAL] CWE-119 CVE-2026-4184: A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unkno A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now publ
nvd
Dlink Dir-816 Firmware vulnerabilities | cvebase