Executive brief
A vulnerability exists in the D-Link DIR-816 wireless router, a device used to provide internet connectivity for home and small office environments. An attacker can remotely execute unauthorized commands on the router by manipulating the port forwarding settings. This could lead to a complete takeover of the device, allowing the attacker to intercept network traffic or disrupt internet services.
Technical details
A command injection vulnerability (CWE-77) exists in the D-Link DIR-816 router firmware version 1.10CNB05_R1B011D88210. The flaw is located within the 'portForward' function, where the 'ip_address' argument is improperly neutralized before being used in a system command. A remote attacker with low privileges can exploit this by sending a specially crafted request to the device's web management interface. Successful exploitation allows for arbitrary command execution on the underlying operating system. Public exploit code is reportedly available.
Affected products
- D-Link DIR-816 1.10CNB05_R1B011D88210
Timeline
- 2026-05-12: disclosed: Vulnerability published on NVD and VulDB.