D-Link DIR-816 A2
cpe:2.3:h:d-link:dir-816:*:*:*:*:*:*:*, +7 more
- 1.10CNB05_R1B011D88210
A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue resides within the DDNS service component, particularly in the '/goform/DDNS' file. This vulnerability allows for improper access control, enabling unauthorized users to manipulate DDNS settings remotely without authentication.
Exploitation of this vulnerability could lead to unauthorized changes in the DDNS configuration, potentially allowing attackers to redirect traffic or create denial-of-service conditions.
To reproduce this vulnerability, send an unauthenticated HTTP POST request to the '/goform/DDNS' endpoint. Include the 'DDNS' header to manipulate the DDNS service settings on the device.
It is recommended to implement proper firewall rules to block unauthorized access to the vulnerable DDNS service.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.