Vulnerabilities > Dlink > DIR 816 Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-08-24 CVE-2021-39510 Command Injection vulnerability in Dlink Dir-816 Firmware 101Cnb04
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.
network
low complexity
dlink CWE-77
critical
9.8
2021-08-24 CVE-2021-39509 Command Injection vulnerability in Dlink Dir-816 Firmware 1.10Cnb05R1B011D88210
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.
network
low complexity
dlink CWE-77
critical
9.8
2021-04-14 CVE-2021-27113 OS Command Injection vulnerability in Dlink Dir-816 Firmware 1.10B05
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices.
network
low complexity
dlink CWE-78
critical
9.8
2021-04-14 CVE-2021-27114 Out-of-bounds Write vulnerability in Dlink Dir-816 Firmware 1.10B05
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices.
network
low complexity
dlink CWE-787
critical
9.8
2021-03-30 CVE-2021-26810 OS Command Injection vulnerability in Dlink Dir-816 Firmware 1.10B05
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability.
network
low complexity
dlink CWE-78
critical
9.8
2019-03-25 CVE-2019-10039 Missing Authentication for Critical Function vulnerability in Dlink Dir-816 Firmware 1.11
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request.
network
low complexity
dlink CWE-306
critical
9.8
2019-03-25 CVE-2019-10040 Missing Authentication for Critical Function vulnerability in Dlink Dir-816 Firmware 1.11
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request.
network
low complexity
dlink CWE-306
critical
9.8
2019-03-25 CVE-2019-10041 Missing Authentication for Critical Function vulnerability in Dlink Dir-816 Firmware 1.11
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request.
network
low complexity
dlink CWE-306
critical
9.8