VendorsD-Linkdir-816_firmware1.10cnb05_r1b011d88210
Vulnerabilities

D-Link DIR-816 1.10cnb05_r1b011d88210

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2024-57684
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
9.8EPSS 0.144
CVE-2021-39509
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
Published 2021-08-24 · Modified
9.8EPSS 0.051
CVE-2025-45931
An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file
Published 2025-06-30 · Modified
9.8EPSS 0.010
CVE-2026-8345
D-Link DIR-816 singlePortForward sub_445E7C command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.032
CVE-2026-8344
D-Link DIR-816 formDMZ.cgi sub_445E7C command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.032
CVE-2026-8346
D-Link DIR-816 portForward command injection
Published 2026-05-11 · Analyzed
8.8EPSS 0.031
CVE-2025-60679
A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated using sprintf() into another 512-byte buffer containing a 29-byte constant. Input exceeding 481 bytes triggers a stack buffer overflow, allowing an attacker who can control /proc/version content to potentially execute arbitrary code on the device.
Published 2025-11-13 · Modified
8.8EPSS 0.007
CVE-2024-13106
D-Link DIR-816 A2 IP QoS form2IPQoSTcAdd access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.272
CVE-2024-13107
D-Link DIR-816 A2 ACL form2LocalAclEditcfg.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.011
CVE-2024-13108
D-Link DIR-816 A2 form2NetSniper.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.010
CVE-2024-13103
D-Link DIR-816 A2 Virtual Service form2AddVrtsrv.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13102
D-Link DIR-816 A2 DDNS Service access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13105
D-Link DIR-816 A2 DHCPD Setting form2Dhcpd.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.008
CVE-2024-13104
D-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access control
Published 2025-01-02 · Analyzed
6.9EPSS 0.007
CVE-2024-57679
An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.006
CVE-2024-57677
An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.006
CVE-2024-57682
An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.005
CVE-2024-57678
An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.004
CVE-2024-57676
An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
6.5EPSS 0.004
CVE-2024-57680
An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
5.3EPSS 0.005
CVE-2024-57681
An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
5.3EPSS 0.005
CVE-2024-57683
An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.
Published 2025-01-16 · Analyzed
4.3EPSS 0.005