VYPR

Dir 816 Firmware

by Dlink

CVEs (75)

  • CVE-2022-37129HigAug 31, 2022
    risk 0.58cvss 8.8epss 0.08

    D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

  • CVE-2025-60679HigNov 13, 2025
    risk 0.57cvss 8.8epss 0.01

    A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and…

  • CVE-2022-37123HigAug 31, 2022
    risk 0.57cvss 8.8epss 0.03

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.

  • CVE-2022-40946HigApr 16, 2023
    risk 0.52cvss 7.5epss 0.08

    On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a cgi-bin/webproc?getpage=html/index.html request.

  • CVE-2022-36620HigAug 31, 2022
    risk 0.51cvss 7.5epss 0.23

    D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.

  • CVE-2025-61577HigOct 9, 2025
    risk 0.49cvss 7.5epss 0.05

    D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2022-42999HigOct 26, 2022
    risk 0.49cvss 7.5epss 0.03

    D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.

  • CVE-2022-36619HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.

  • CVE-2022-37133HigAug 22, 2022
    risk 0.49cvss 7.5epss 0.01

    D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.

  • CVE-2019-7642HigMar 25, 2019
    risk 0.49cvss 7.5epss 0.03

    D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04),…

  • CVE-2019-10042HigMar 25, 2019
    risk 0.49cvss 7.5epss 0.02

    The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.

  • CVE-2026-4180HigMar 16, 2026
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper access controls. The attack may be initiated remotely. The…

  • CVE-2025-5621HigJun 5, 2025
    risk 0.48cvss 7.3epss 0.07

    A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The…

  • CVE-2025-5620HigJun 5, 2025
    risk 0.48cvss 7.3epss 0.07

    A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the…

  • CVE-2025-29743MedApr 22, 2025
    risk 0.42cvss 6.5epss 0.01

    D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

  • CVE-2024-57682MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.

  • CVE-2024-57679MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

  • CVE-2024-57678MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

  • CVE-2024-57677MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.

  • CVE-2024-57676MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.