D-Link DIR-816
cpe:2.3:h:d-link:dir-816:*:*:*:*:*:*:*, +12 more
- dir-816_a2_firmware
- dir-816l_firmware
- dir-816_a1_firmware
- 816A2_FWv1.10CNB05_R1B011D88210
An access control vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 816A2_FWv1.10CNB05_R1B011D88210. The issue allows unauthenticated attackers to manipulate the port triggering settings of the device by sending a crafted POST request. This vulnerability arises from inadequate access controls in the affected CGI component, form2PortriggerRule.cgi.
Exploitation of this vulnerability allows for unauthorized modification of the port triggering settings on the affected D-Link DIR-816 router.
To reproduce this vulnerability, send a POST request to the form2PortriggerRule.cgi endpoint on a D-Link DIR-816 router running the vulnerable firmware version. The request must be crafted to include the desired port triggering settings, which the router will apply without requiring authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.