VendorsD-Linkdir-816_firmwareall versions
Vulnerabilities

D-Link DIR-816

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

73CVEs
CVE-2025-5623
D-Link DIR-816 qosClassifier stack-based overflow
Published 2025-06-05 · Analyzed
10.0EPSS 0.185
CVE-2022-29322
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.
Published 2022-05-10 · Modified
10.0EPSS 0.169
CVE-2022-28915
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.
Published 2022-05-10 · Modified
10.0EPSS 0.067
CVE-2021-26810
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.
Published 2021-03-30 · Modified
10.0EPSS 0.049
CVE-2022-29323
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.
Published 2022-05-10 · Modified
10.0EPSS 0.039
CVE-2022-29321
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.
Published 2022-05-10 · Modified
10.0EPSS 0.039
CVE-2022-29324
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.
Published 2022-05-10 · Modified
10.0EPSS 0.039
CVE-2022-29327
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.
Published 2022-05-10 · Modified
10.0EPSS 0.038
CVE-2022-29326
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.
Published 2022-05-10 · Modified
10.0EPSS 0.038
CVE-2022-29325
D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.
Published 2022-05-10 · Modified
10.0EPSS 0.038
CVE-2021-27113
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.
Published 2021-04-14 · Modified
10.0EPSS 0.035
CVE-2025-5630
D-Link DIR-816 form2lansetup.cgi stack-based overflow
Published 2025-06-05 · Analyzed
10.0EPSS 0.026
CVE-2019-10040
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /goform/SystemCommand to execute a system command without authentication.
Published 2019-03-25 · Modified
10.0EPSS 0.025
CVE-2025-5622
D-Link DIR-816 wirelessApcli_5g stack-based overflow
Published 2025-06-05 · Analyzed
10.0EPSS 0.025
CVE-2025-5624
D-Link DIR-816 QoSPortSetup stack-based overflow
Published 2025-06-05 · Analyzed
10.0EPSS 0.025
CVE-2026-4181
D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow
Published 2026-03-15 · Analyzed
10.0EPSS 0.012
CVE-2026-4184
D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow
Published 2026-03-15 · Analyzed
10.0EPSS 0.012
CVE-2026-4183
D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow
Published 2026-03-15 · Analyzed
10.0EPSS 0.012
CVE-2026-4182
D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow
Published 2026-03-15 · Analyzed
10.0EPSS 0.011
CVE-2022-37130
In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability
Published 2022-08-31 · Modified
9.8EPSS 0.269
CVE-2021-27114
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.
Published 2021-04-14 · Modified
9.8EPSS 0.246
CVE-2022-37128
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
Published 2022-08-31 · Modified
9.8EPSS 0.217
CVE-2022-37134
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.
Published 2022-08-22 · Modified
9.8EPSS 0.217
CVE-2024-57684
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
9.8EPSS 0.144
CVE-2021-39510
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
Published 2021-08-24 · Modified
9.8EPSS 0.086
CVE-2025-5620
D-Link DIR-816 setipsec_config os command injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.077
CVE-2025-5621
D-Link DIR-816 qosClassifier os command injection
Published 2025-06-04 · Analyzed
9.8EPSS 0.075
CVE-2021-39509
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
Published 2021-08-24 · Modified
9.8EPSS 0.051
CVE-2022-37125
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
Published 2022-08-31 · Modified
9.8EPSS 0.032
CVE-2021-31326
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.
Published 2022-03-23 · Modified
9.8EPSS 0.022
CVE-2023-24331
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.
Published 2024-02-21 · Analyzed
9.8EPSS 0.021
CVE-2023-39637
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
Published 2023-09-12 · Modified
9.8EPSS 0.021
CVE-2024-24321
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
Published 2024-02-08 · Modified
9.8EPSS 0.019
CVE-2019-10039
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setSysAdm to edit the web or system account without authentication.
Published 2019-03-25 · Modified
9.8EPSS 0.019
CVE-2019-10041
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.
Published 2019-03-25 · Modified
9.8EPSS 0.015
CVE-2026-4180
D-Link DIR-816 goahead redirect.asp access control
Published 2026-03-15 · Analyzed
9.8EPSS 0.014
CVE-2022-43000
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.
Published 2022-10-26 · Modified
9.8EPSS 0.012
CVE-2022-43001
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.
Published 2022-10-26 · Modified
9.8EPSS 0.012
CVE-2022-43002
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.
Published 2022-10-26 · Modified
9.8EPSS 0.012
CVE-2022-43003
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.
Published 2022-10-26 · Modified
9.8EPSS 0.012
1 / 2Next →