Dlink
Dlink Dir-816 Firmware: vulnerabilidades y CVE
Dlink Dir-816 Firmware tiene 73 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 35 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE73
Últimos 12 meses10
Críticas35
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8346 | Baja (2.1) | 5.0% | — | 12 may 2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be… |
| CVE-2026-8345 | Baja (2.1) | 5.0% | — | 11 may 2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address… |
| CVE-2026-8344 | Baja (2.1) | 5.0% | — | 11 may 2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is… |
| CVE-2026-4184 | Alta (8.9) | 1.9% | — | 16 mar 2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the… |
| CVE-2026-4183 | Alta (8.9) | 1.9% | — | 16 mar 2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue… |
| CVE-2026-4182 | Alta (8.9) | 1.9% | — | 16 mar 2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument… |
| CVE-2026-4181 | Alta (8.9) | 1.9% | — | 16 mar 2026 | A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument… |
| CVE-2026-4180 | Media (5.5) | 3.0% | — | 16 mar 2026 | A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper… |
| CVE-2025-60679 | Alta (8.8) | 0.67% | — | 13 nov 2025 | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs… |
| CVE-2025-61577 | Alta (7.5) | 5.7% | — | 9 oct 2025 | D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the dir_setWanWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) via… |
| CVE-2025-45931 | Crítica (9.8) | 0.96% | — | 30 jun 2025 | An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file |
| CVE-2025-5630 | Crítica (9.3) | 2.6% | — | 5 jun 2025 | A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to… |
| CVE-2025-5624 | Crítica (9.3) | 2.5% | — | 5 jun 2025 | A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument… |
| CVE-2025-5623 | Crítica (9.3) | 19% | — | 5 jun 2025 | A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument… |
| CVE-2025-5622 | Crítica (9.3) | 2.5% | — | 5 jun 2025 | A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument… |
| CVE-2025-5621 | Media (6.9) | 7.5% | — | 5 jun 2025 | A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument… |
| CVE-2025-5620 | Media (6.9) | 7.7% | — | 5 jun 2025 | A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP… |
| CVE-2025-29743 | Media (6.5) | 1.0% | — | 22 abr 2025 | D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting. |
| CVE-2025-1392 | Media (5.1) | 8.7% | — | 17 feb 2025 | A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic. Affected by this vulnerability is an unknown functionality of the file… |
| CVE-2024-57684 | Crítica (9.8) | 14% | — | 16 ene 2025 | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request. |
| CVE-2024-57683 | Media (4.3) | 0.54% | — | 16 ene 2025 | An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request. |
| CVE-2024-57682 | Media (6.5) | 0.47% | — | 16 ene 2025 | An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to access sensitive information via a crafted POST request. |
| CVE-2024-57681 | Media (5.3) | 0.51% | — | 16 ene 2025 | An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request. |
| CVE-2024-57680 | Media (5.3) | 0.51% | — | 16 ene 2025 | An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request. |
| CVE-2024-57679 | Media (6.5) | 0.57% | — | 16 ene 2025 | An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request. |
| CVE-2024-57678 | Media (6.5) | 0.43% | — | 16 ene 2025 | An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request. |
| CVE-2024-57677 | Media (6.5) | 0.57% | — | 16 ene 2025 | An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request. |
| CVE-2024-57676 | Media (6.5) | 0.43% | — | 16 ene 2025 | An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request. |
| CVE-2024-13108 | Media (6.9) | 0.99% | — | 2 ene 2025 | A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper… |
| CVE-2024-13107 | Media (6.9) | 1.1% | — | 2 ene 2025 | A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been classified as critical. This affects an unknown part of the file /goform/form2LocalAclEditcfg.cgi of the component ACL Handler. The… |