VendorsD-Linkdir-816_firmwareall versions
Vulnerabilities

D-Link DIR-816

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

73CVEs
CVE-2022-42998
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.
Published 2022-10-26 · Modified
9.8EPSS 0.012
CVE-2025-45931
An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file
Published 2025-06-30 · Modified
9.8EPSS 0.010
CVE-2022-37129
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.
Published 2022-08-31 · Modified
8.8EPSS 0.083
CVE-2026-8345
D-Link DIR-816 singlePortForward sub_445E7C command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.032
CVE-2026-8344
D-Link DIR-816 formDMZ.cgi sub_445E7C command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.032
CVE-2026-8346
D-Link DIR-816 portForward command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.031
CVE-2022-37123
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
Published 2022-08-31 · Modified
8.8EPSS 0.027
CVE-2025-60679
A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated using sprintf() into another 512-byte buffer containing a 29-byte constant. Input exceeding 481 bytes triggers a stack buffer overflow, allowing an attacker who can control /proc/version content to potentially execute arbitrary code on the device.
Published 2025-11-13 · Modified
8.8EPSS 0.007
CVE-2019-10042
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.
Published 2019-03-25 · Modified
7.8EPSS 0.017
CVE-2022-36620
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
Published 2022-08-31 · Modified
7.5EPSS 0.237
CVE-2025-61577
D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2025-10-09 · Analyzed
7.5EPSS 0.057
CVE-2022-42999
D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.
Published 2022-10-26 · Modified
7.5EPSS 0.027
CVE-2019-7642
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).
Published 2019-03-25 · Modified
7.5EPSS 0.026
CVE-2022-37133
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
Published 2022-08-22 · Modified
7.5EPSS 0.013
CVE-2022-36619
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
Published 2022-08-31 · Modified
7.5EPSS 0.012
CVE-2024-13106
D-Link DIR-816 A2 IP QoS form2IPQoSTcAdd access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.272
CVE-2024-13107
D-Link DIR-816 A2 ACL form2LocalAclEditcfg.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.011
CVE-2024-13108
D-Link DIR-816 A2 form2NetSniper.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.010
CVE-2024-13103
D-Link DIR-816 A2 Virtual Service form2AddVrtsrv.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13102
D-Link DIR-816 A2 DDNS Service access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13105
D-Link DIR-816 A2 DHCPD Setting form2Dhcpd.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13104
D-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.007
CVE-2025-29743
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.
Published 2025-04-22 · Analyzed
6.5EPSS 0.010
CVE-2024-57677
An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.006
CVE-2024-57679
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.006
CVE-2024-57682
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.005
CVE-2024-57678
An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.004
CVE-2024-57676
An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.004
CVE-2025-1392
D-Link DIR-816 index.html cross site scripting
Published 2025-02-17 · Analyzed
5.4EPSS 0.080
CVE-2024-0717
D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure
Published 2024-01-19 · Modified
5.3EPSS 0.182
CVE-2024-57681
An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
5.3EPSS 0.005
CVE-2024-57680
An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
5.3EPSS 0.005
CVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
4.3EPSS 0.005
← Prev2 / 2