D-Link DIR-816 A2 IP QoS Handler Access Control Vulnerability

Vulnerability

A critical vulnerability has been identified in the D-Link DIR-816 A2 router, specifically in version 1.10CNB05_R1B011D88210. The issue arises from improper access controls in the IP QoS Handler component, particularly within the file '/goform/form2IPQoSTcAdd'. This vulnerability allows for unauthorized access and manipulation, and can be exploited remotely.

Impact

Exploitation of this vulnerability could lead to unauthorized access and manipulation of the router's IP QoS settings.

Reproduction

The vulnerability can be reproduced by sending a request to the '/goform/form2IPQoSTcAdd' endpoint. This request can be made remotely, and does not require any special privileges or user interaction.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.6
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.9
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.