📦 Dir 816 Firmware

by Dlink

🔍 What is Dir 816 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-45931

CRITICAL CVSS 9.8 Jun 30, 2025

This critical vulnerability in D-Link DIR-816-A2 routers allows remote attackers to execute arbitrary code via the system() function in the goahead binary. Attackers can gain complete control of affec...

CVE-2025-5630

CRITICAL CVSS 9.8 Jun 5, 2025

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the web interface's form2lansetup.cgi endpoint. Attackers c...

CVE-2025-5624

CRITICAL CVSS 9.8 Jun 5, 2025

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the QoS configuration function. Attackers can exploit this ...

CVE-2025-5622

CRITICAL CVSS 9.8 Jun 5, 2025

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the wireless configuration function. Attackers can exploit ...

CVE-2024-57684

CRITICAL CVSS 9.8 Jan 16, 2025

This vulnerability allows unauthenticated attackers to remotely configure the DMZ (Demilitarized Zone) service on affected D-Link routers via a crafted POST request to formDMZ.cgi. Attackers can redir...

CVE-2023-24331

CRITICAL CVSS 9.8 Feb 21, 2024

This CVE describes a command injection vulnerability in D-Link DIR-816 routers that allows attackers to execute arbitrary commands via the urlAdd parameter. Attackers can gain full control of affected...

CVE-2024-24321

CRITICAL CVSS 9.8 Feb 8, 2024

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816A2 routers via a command injection flaw in the wizardstep4_ssid_2 parameter. Attackers can gain full control of af...

CVE-2023-39637

CRITICAL CVSS 9.8 Sep 12, 2023

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-816 A2 routers via the /goform/Diagnosis component. Attackers can gain full control of affected devices, potentia...

CVE-2022-28915

CRITICAL CVSS 9.8 May 10, 2022

This CVE describes a command injection vulnerability in D-Link DIR-816 routers that allows attackers to execute arbitrary commands on the device. Attackers can exploit this by injecting malicious comm...

CVE-2022-29322

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 routers via a stack overflow in the DHCP configuration handler. Attackers can exploit this by sending specially c...

CVE-2022-29324

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 routers via a stack overflow in the web interface. Attackers can exploit this without authentication to gain full...

CVE-2022-29326

CRITICAL CVSS 9.8 May 10, 2022

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-816 routers via a stack overflow in the addhostfilter parameter. Attackers can exploit this without authentication to...

CVE-2021-31326

CRITICAL CVSS 9.8 Mar 24, 2022

This vulnerability allows unauthenticated attackers to remotely reset D-Link DIR-816 A2 routers to factory defaults via a crafted HTTP request. Attackers can exploit this by sending a specially crafte...

CVE-2021-39509

CRITICAL CVSS 9.8 Aug 24, 2021

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-816 routers through command injection in the web interface. Attackers can exploit this by sending specially craft...

CVE-2021-27113

CRITICAL CVSS 9.8 Apr 14, 2021

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-816 A2 routers by injecting shell metacharacters into HTTP parameters. Attackers can gain full control of affecte...

CVE-2021-26810

CRITICAL CVSS 9.8 Mar 30, 2021

CVE-2021-26810 is a remote command injection vulnerability in D-Link DIR-816 A2 routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the web interface...

CVE-2025-61577

HIGH CVSS 7.5 Oct 9, 2025

A stack overflow vulnerability in D-Link DIR-816A2 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the statuscheckpppoeuser parameter. This affects users of DIR-8...

CVE-2025-5621

HIGH CVSS 7.3 Jun 5, 2025

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary operating system commands via command injection in the qosClassifier function. Attackers can exploit ...

CVE-2024-57677

MEDIUM CVSS 6.5 Jan 16, 2025

This vulnerability allows unauthenticated attackers to modify WAN service settings on D-Link DIR-816 routers via a crafted POST request to form2Wan.cgi. It affects D-Link DIR-816A2 routers running vul...

CVE-2024-57679

MEDIUM CVSS 6.5 Jan 16, 2025

This vulnerability allows unauthenticated attackers to remotely configure the 2.4G and 5G repeater services on affected D-Link routers. Attackers can change wireless network settings without authentic...

CVE-2024-57681

MEDIUM CVSS 5.3 Jan 16, 2025

An access control vulnerability in D-Link DIR-816 routers allows unauthenticated attackers to modify the agl service configuration via crafted POST requests to form2alg.cgi. This affects D-Link DIR-81...

CVE-2024-57683

MEDIUM CVSS 4.3 Jan 16, 2025

This vulnerability allows unauthenticated attackers to modify URL filter settings on affected D-Link DIR-816A2 routers via a crafted POST request. Attackers can bypass authentication requirements to c...

CVE-2024-13106

MEDIUM CVSS 5.3 Jan 2, 2025

This vulnerability in D-Link DIR-816 routers allows unauthorized access to the IP QoS configuration handler due to improper access controls. Attackers can remotely exploit this to modify Quality of Se...

CVE-2024-13104

MEDIUM CVSS 5.3 Jan 2, 2025

This vulnerability allows remote attackers to bypass authentication and access WiFi settings on affected D-Link DIR-816 A2 routers. Attackers can modify wireless network configurations without proper ...