Dlink Dir-816 Firmware vulnerabilities
73 known vulnerabilities affecting dlink/dir-816_firmware.
Total CVEs
73
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL42HIGH13MEDIUM18
Vulnerabilities
Page 3 of 4
CVE-2024-24321P3CRITICALCVSS 9.8v1.10cnb052024-02-08
CVE-2024-24321 [CRITICAL] CWE-77 CVE-2024-24321: An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the w
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
nvd
CVE-2025-45931P3CRITICALCVSS 9.8v1.10cnb05_r1b011d882102025-06-30
CVE-2025-45931 [CRITICAL] CWE-77 CVE-2025-45931: An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute a
An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file
nvd
CVE-2019-10041P3CRITICALCVSS 9.8v1.112019-03-25
CVE-2019-10041 [CRITICAL] CWE-306 CVE-2019-10041: The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.
nvd
CVE-2022-42998P3CRITICALCVSS 9.8v1.10b052022-10-26
CVE-2022-42998 [CRITICAL] CWE-787 CVE-2022-42998: D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /go
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.
nvd
CVE-2022-43001P3CRITICALCVSS 9.8v1.10b052022-10-26
CVE-2022-43001 [CRITICAL] CWE-787 CVE-2022-43001: D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.
nvd
CVE-2022-43002P3CRITICALCVSS 9.8v1.10b052022-10-26
CVE-2022-43002 [CRITICAL] CWE-787 CVE-2022-43002: D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd pa
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.
nvd
CVE-2022-43003P3CRITICALCVSS 9.8v1.10b052022-10-26
CVE-2022-43003 [CRITICAL] CWE-787 CVE-2022-43003: D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.
nvd
CVE-2022-43000P3CRITICALCVSS 9.8v1.10b052022-10-26
CVE-2022-43000 [CRITICAL] CWE-787 CVE-2022-43000: D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd par
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.
nvd
CVE-2022-36620P3HIGHCVSS 7.5v1.10cnb042022-08-31
CVE-2022-36620 [HIGH] CWE-1284 CVE-2022-36620: D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /go
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
nvd
CVE-2024-13106P3MEDIUMCVSS 5.3v1.10cnb05_r1b011d882102025-01-02
CVE-2024-13106 [MEDIUM] CWE-266 CVE-2024-13106: A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Af
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the publ
nvd
CVE-2025-61577P3HIGHCVSS 7.5v1.10cnb052025-10-09
CVE-2025-61577 [HIGH] CWE-121 CVE-2025-61577: D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuse
D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2022-42999P3HIGHCVSS 7.5v1.10b052022-10-26
CVE-2022-42999 [HIGH] CWE-78 CVE-2022-42999: D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via
D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.
nvd
CVE-2019-7642P3HIGHCVSS 7.5v2.062019-03-25
CVE-2019-7642 [HIGH] CWE-306 CVE-2019-7642: D-Link routers with the mydlink feature have some web interfaces without authentication requirements
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.1
nvd
CVE-2024-0717P3MEDIUMCVSS 5.3≤ 2024-01-122024-01-19
CVE-2024-0717 [MEDIUM] CWE-200 CVE-2024-0717: A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DI
A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530,
nvd
CVE-2019-10042P3HIGHCVSS 7.5v1.112019-03-25
CVE-2019-10042 [HIGH] CWE-306 CVE-2019-10042: The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.
nvd
CVE-2022-36619P3HIGHCVSS 7.5v1.10cnb042022-08-31
CVE-2022-36619 [HIGH] CWE-306 CVE-2022-36619: In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setM
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
nvd
CVE-2022-37133P3HIGHCVSS 7.5v1.10cnb042022-08-22
CVE-2022-37133 [HIGH] CWE-404 CVE-2022-37133: D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
nvd
CVE-2024-57679P3MEDIUMCVSS 6.5v1.10cnb05_r1b011d882102025-01-16
CVE-2024-57679 [MEDIUM] CWE-863 CVE-2024-57679: An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.
nvd
CVE-2024-57677P3MEDIUMCVSS 6.5v1.10cnb05_r1b011d882102025-01-16
CVE-2024-57677 [MEDIUM] CWE-863 CVE-2024-57677: An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allo
An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.
nvd
CVE-2024-57676P3MEDIUMCVSS 6.5v1.10cnb05_r1b011d882102025-01-16
CVE-2024-57676 [MEDIUM] CWE-863 CVE-2024-57676: An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011
An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.
nvd