VendorsD-Linkdir-816l_firmware2.06.b09
Vulnerabilities

D-Link dir-816l Firmware 2.06.b09

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
Published 2025-11-14 · Analyzed
10.0EPSS 0.024
CVE-2020-15893
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) field of the SSDP M-SEARCH discover packet.
Published 2020-07-22 · Modified
9.8EPSS 0.209
CVE-2025-13189
D-Link DIR-816L gena.cgi genacgi_main stack-based overflow
Published 2025-11-15 · Analyzed
9.8EPSS 0.009
CVE-2025-13191
D-Link DIR-816L soap.cgi soapcgi_main stack-based overflow
Published 2025-11-15 · Analyzed
9.8EPSS 0.009
CVE-2025-13190
D-Link DIR-816L __ajax_exporer.sgi scandir_main stack-based overflow
Published 2025-11-15 · Analyzed
9.0EPSS 0.008
CVE-2020-15894
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. There exists an exposed administration function in getcfg.php, which can be used to call various services. It can be utilized by an attacker to retrieve various sensitive information, such as admin login credentials, by setting the value of _POST_SERVICES in the query string to DEVICE.ACCOUNT.
Published 2020-07-22 · Modified
7.5EPSS 0.017
CVE-2020-15895
An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it's printed on the webpage.
Published 2020-07-22 · Modified
6.1EPSS 0.028
CVE-2020-25786
webinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: this is typically not exploitable because of URL encoding (except in Internet Explorer) and because a web page cannot specify that a client should make an additional HTTP request with an arbitrary Referer header
Published 2020-09-19 · Modified
6.1EPSS 0.010