D-Link DIR-816 Access Control Vulnerability in form2Wan.cgi Allowing Unauthenticated WAN Service Modification

Vulnerability

An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. This vulnerability allows unauthenticated attackers to manipulate the WAN service settings of the device by sending a crafted POST request. The issue arises in the form2Wan.cgi component, where inadequate access controls permit unauthorized modifications to critical network configurations.

Impact

Exploitation of this vulnerability allows for unauthorized changes to the WAN service settings of the affected router, potentially leading to unauthorized network access or disruption of service.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.6
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.