VendorsD-Linkdir-816a2
Vulnerabilities

D-Link dir-816 a2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

58CVEs
CVE-2022-37133
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
Published 2022-08-22 · Modified
7.5EPSS 0.013
CVE-2022-36619
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
Published 2022-08-31 · Modified
7.5EPSS 0.012
CVE-2024-13106
D-Link DIR-816 A2 IP QoS form2IPQoSTcAdd access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.272
CVE-2024-13107
D-Link DIR-816 A2 ACL form2LocalAclEditcfg.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.011
CVE-2024-13108
D-Link DIR-816 A2 form2NetSniper.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.010
CVE-2024-13103
D-Link DIR-816 A2 Virtual Service form2AddVrtsrv.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13105
D-Link DIR-816 A2 DHCPD Setting form2Dhcpd.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13102
D-Link DIR-816 A2 DDNS Service access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13104
D-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.007
CVE-2025-29743
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
Published 2025-04-22 · Analyzed
6.5EPSS 0.010
CVE-2024-57679
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.006
CVE-2024-57677
An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.006
CVE-2024-57682
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.005
CVE-2024-57678
An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.004
CVE-2024-57676
An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.004
CVE-2024-57680
An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
5.3EPSS 0.005
CVE-2024-57681
An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
5.3EPSS 0.005
CVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
4.3EPSS 0.005
← Prev2 / 2