VendorsD-Linkdir-816lall versions
Vulnerabilities

D-Link DIR-816L

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
Published 2025-11-14 · Analyzed
10.0EPSS 0.024
CVE-2022-28956
An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.
Published 2022-05-18 · Modified
9.8EPSS 0.227
CVE-2020-15893
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
Published 2020-07-22 · Modified
9.8EPSS 0.209
CVE-2025-9727
D-Link DIR-816L soap.cgi soapcgi_main os command injection
Published 2025-08-31 · Analyzed
9.8EPSS 0.048
CVE-2025-13189
D-Link DIR-816L gena.cgi genacgi_main stack-based overflow
Published 2025-11-15 · Analyzed
9.8EPSS 0.009
CVE-2025-13191
D-Link DIR-816L soap.cgi soapcgi_main stack-based overflow
Published 2025-11-15 · Analyzed
9.8EPSS 0.009
CVE-2025-13190
D-Link DIR-816L __ajax_exporer.sgi scandir_main stack-based overflow
Published 2025-11-15 · Analyzed
9.0EPSS 0.008
CVE-2025-7836
D-Link DIR-816L Environment Variable cgibin lxmldbc_system command injection
Published 2025-07-19 · Analyzed
8.8EPSS 0.052
CVE-2022-28955
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.
Published 2022-05-18 · Modified
7.5EPSS 0.397
CVE-2019-7642
D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).
Published 2019-03-25 · Modified
7.5EPSS 0.026
CVE-2020-15894
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.
Published 2020-07-22 · Modified
7.5EPSS 0.017
CVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.
Published 2015-11-18 · Modified
6.81 PoCEPSS 0.032
CVE-2025-46176
Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.
Published 2025-05-23 · Analyzed
6.5EPSS 0.004
CVE-2020-15895
An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.
Published 2020-07-22 · Modified
6.1EPSS 0.028
CVE-2020-25786
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header
Published 2020-09-19 · Modified
6.1EPSS 0.010