D-Link DIR-816 OS Command Injection Vulnerability

Vulnerability

A critical OS command injection vulnerability has been identified in the D-Link DIR-816 router, specifically in the 1.10CNB05 firmware version. The issue arises in the 'qosClassifier' function within the file '/goform/qosClassifier', where the 'dip_address' and 'sip_address' arguments can be manipulated to inject and execute arbitrary OS commands. This vulnerability can be exploited remotely, without authentication, and affects products that are no longer supported by the manufacturer.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/goform/qosClassifier' with crafted 'dip_address' or 'sip_address' parameters that are excessively long. This causes a stack overflow, which can be exploited to execute arbitrary code. The router will crash as a result, disrupting its normal service.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
9.1
remediation
0.0
relevance
0.2
threat
6.5
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.