Dlink Dir-816 Firmware vulnerabilities
73 known vulnerabilities affecting dlink/dir-816_firmware.
Total CVEs
73
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL42HIGH13MEDIUM18
Vulnerabilities
Page 2 of 4
CVE-2026-4181P2CRITICALCVSS 9.8v1.10cnb052026-03-16
CVE-2026-4181 [CRITICAL] CWE-119 CVE-2026-4181: A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of
A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public a
nvd
CVE-2026-4182P2CRITICALCVSS 9.8v1.10cnb052026-03-16
CVE-2026-4182 [CRITICAL] CWE-119 CVE-2026-4182: A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the
A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to th
nvd
CVE-2022-28915P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-28915 [CRITICAL] CWE-78 CVE-2022-28915: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the adm
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
nvd
CVE-2021-39510P2CRITICALCVSS 9.8v101cnb042021-08-24
CVE-2021-39510 [CRITICAL] CWE-77 CVE-2021-39510: An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request pa
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
nvd
CVE-2021-26810P2CRITICALCVSS 9.8v1.10b052021-03-30
CVE-2021-26810 [CRITICAL] CWE-78 CVE-2021-26810: D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parame
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.
nvd
CVE-2021-27113P2CRITICALCVSS 9.8v1.10b052021-04-14
CVE-2021-27113 [CRITICAL] CWE-78 CVE-2021-27113: An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.
nvd
CVE-2026-4180P2CRITICALCVSS 9.8v1.10cnb052026-03-16
CVE-2026-4180 [CRITICAL] CWE-266 CVE-2026-4180: A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown funct
A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper access controls. The attack may be initiated remotely. The exploit is publicly available and might be used. This vulnerability only affe
nvd
CVE-2021-31326P2CRITICALCVSS 9.8v1.10cnb052022-03-24
CVE-2021-31326 [CRITICAL] CWE-287 CVE-2021-31326: D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a cr
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.
nvd
CVE-2022-29324P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29324 [CRITICAL] CWE-787 CVE-2022-29324: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.
nvd
CVE-2022-29321P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29321 [CRITICAL] CWE-787 CVE-2022-29321: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.
nvd
CVE-2022-29326P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29326 [CRITICAL] CWE-787 CVE-2022-29326: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parame
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.
nvd
CVE-2022-29327P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29327 [CRITICAL] CWE-787 CVE-2022-29327: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.
nvd
CVE-2022-29325P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29325 [CRITICAL] CWE-787 CVE-2022-29325: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter paramet
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.
nvd
CVE-2022-37125P2CRITICALCVSS 9.8v1.10cnb042022-08-31
CVE-2022-37125 [CRITICAL] CWE-77 CVE-2022-37125: D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
nvd
CVE-2023-39637P2CRITICALCVSS 9.8v1.10b052023-09-12
CVE-2023-39637 [CRITICAL] CWE-77 CVE-2023-39637: D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the compo
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
nvd
CVE-2022-29323P2CRITICALCVSS 9.8v1.10cnb042022-05-10
CVE-2022-29323 [CRITICAL] CWE-787 CVE-2022-29323: D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /go
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.
nvd
CVE-2019-10040P3CRITICALCVSS 9.8v1.112019-03-25
CVE-2019-10040 [CRITICAL] CWE-306 CVE-2019-10040: The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /goform/SystemCommand to execute a system command without authentication.
nvd
CVE-2025-60679P3HIGHCVSS 8.8v1.10cnb05_r1b011d882102025-11-13
CVE-2025-60679 [HIGH] CWE-121 CVE-2025-60679: A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.
A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated using sprintf() into another 512-byte buffer containing a
nvd
CVE-2019-10039P3CRITICALCVSS 9.8v1.112019-03-25
CVE-2019-10039 [CRITICAL] CWE-306 CVE-2019-10039: The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setSysAdm to edit the web or system account without authentication.
nvd
CVE-2022-37123P2HIGHCVSS 8.8v1.10cnb042022-08-31
CVE-2022-37123 [HIGH] CWE-78 CVE-2022-37123: D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
nvd