VYPR

DIR-816A2 router firmware

by Dlink

CVEs (6)

  • CVE-2025-60679HigNov 13, 2025
    risk 0.57cvss 8.8epss 0.01

    A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and…

  • CVE-2025-60674MedNov 13, 2025
    risk 0.44cvss 6.8epss 0.01

    A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets…

  • CVE-2025-60676MedNov 13, 2025
    risk 0.43cvss 6.5epss 0.03

    An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell…

  • CVE-2025-60673MedNov 13, 2025
    risk 0.43cvss 6.5epss 0.04

    An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct…

  • CVE-2025-60672MedNov 13, 2025
    risk 0.43cvss 6.5epss 0.04

    An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later…

  • CVE-2021-27342MedMay 17, 2021
    risk 0.39cvss 5.9epss 0.05

    An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0.2 allows a remote attacker to circumvent the anti-brute-force cool-down delay period via a timing-based side-channel attack