D-Link DIR-816 Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the D-Link DIR-816 router, specifically in the firmware version 1.10CNB05_R1B011D88210. The issue arises in the 'formDMZ.cgi' file, where the 'DMZIPAddress' parameter is not properly validated before being saved to the device's NVRAM. This flaw allows for remote exploitation, as the injected command is executed through a system command execution function.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send a request to the 'formDMZ.cgi' endpoint with a crafted 'DMZIPAddress' parameter that includes shell metacharacters. Ensure that 'DMZEnabled' is set to IP mode, as this is the only configuration that allows the weak validation to be bypassed. Once the command injection is successful, the injected command will be executed on the device.

Added: May 11, 2026, 10:29 PM
Updated: May 11, 2026, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.2
remediation
0.0
relevance
8.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.