Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-0921

Disclosure Date: January 26, 2024 (last updated February 03, 2024)
A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setDeviceSettings of the component Web Interface. The manipulation of the argument statuscheckpppoeuser leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252139.
Attacker Value
Unknown

CVE-2022-37130

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability
Attacker Value
Unknown

CVE-2022-37129

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.
Attacker Value
Unknown

CVE-2022-37123

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
Attacker Value
Unknown

CVE-2022-36619

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
Attacker Value
Unknown

CVE-2022-37125

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
Attacker Value
Unknown

CVE-2022-36620

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
Attacker Value
Unknown

CVE-2022-37128

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
Attacker Value
Unknown

CVE-2022-37134

Disclosure Date: August 22, 2022 (last updated October 08, 2023)
D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.
Attacker Value
Unknown

CVE-2022-37133

Disclosure Date: August 22, 2022 (last updated October 08, 2023)
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.