VendorsD-Linkdir-816_a2all versions
Vulnerabilities

D-Link DIR-816 A2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2018-17064
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked.
Published 2018-09-15 · Modified
10.0EPSS 0.074
CVE-2018-17066
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter.
Published 2018-09-15 · Modified
10.0EPSS 0.073
CVE-2018-11013
Stack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows unauthenticated remote attackers to execute arbitrary code via a request with a long HTTP Host header.
Published 2018-05-13 · Modified
10.0EPSS 0.064
CVE-2018-17063
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters.
Published 2018-09-15 · Modified
10.0EPSS 0.041
CVE-2018-17068
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter.
Published 2018-09-15 · Modified
10.0EPSS 0.037
CVE-2018-17065
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address.
Published 2018-09-15 · Modified
10.0EPSS 0.019
CVE-2018-17067
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address.
Published 2018-09-15 · Modified
10.0EPSS 0.019
CVE-2024-0921
D-Link DIR-816 A2 Web Interface setDeviceSettings os command injection
Published 2024-01-26 · Modified
9.8EPSS 0.376
CVE-2023-43237
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.
Published 2023-09-21 · Modified
9.8EPSS 0.144
CVE-2023-43239
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.
Published 2023-09-21 · Modified
9.8EPSS 0.144
CVE-2023-43240
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.
Published 2023-09-21 · Modified
9.8EPSS 0.144
CVE-2018-20305
D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.
Published 2018-12-20 · Modified
9.8EPSS 0.041
CVE-2023-43238
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.
Published 2023-09-21 · Modified
9.8EPSS 0.013
CVE-2023-43236
D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.
Published 2023-09-21 · Modified
9.8EPSS 0.011
CVE-2025-44835
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary commands via shell.
Published 2025-05-01 · Analyzed
6.3EPSS 0.011