VendorsD-Linkdir-816lany version
Vulnerabilities

D-Link DIR-816L any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
Published 2025-11-14 · Analyzed
10.0EPSS 0.024
CVE-2022-28956
An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload.
Published 2022-05-18 · Modified
9.8EPSS 0.227
CVE-2025-9727
D-Link DIR-816L soap.cgi soapcgi_main os command injection
Published 2025-08-31 · Analyzed
9.8EPSS 0.048
CVE-2025-13189
D-Link DIR-816L gena.cgi genacgi_main stack-based overflow
Published 2025-11-15 · Analyzed
9.8EPSS 0.009
CVE-2025-13191
D-Link DIR-816L soap.cgi soapcgi_main stack-based overflow
Published 2025-11-15 · Analyzed
9.8EPSS 0.009
CVE-2025-13190
D-Link DIR-816L __ajax_exporer.sgi scandir_main stack-based overflow
Published 2025-11-15 · Analyzed
9.0EPSS 0.008
CVE-2025-7836
D-Link DIR-816L Environment Variable cgibin lxmldbc_system command injection
Published 2025-07-19 · Analyzed
8.8EPSS 0.052
CVE-2022-28955
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.
Published 2022-05-18 · Modified
7.5EPSS 0.397
CVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.
Published 2015-11-18 · Modified
6.81 PoCEPSS 0.032
CVE-2025-46176
Hardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary commands via firmware analysis.
Published 2025-05-23 · Analyzed
6.5EPSS 0.004