D Link · D-Link Dir-816 A2 · CVE-2024-0921
**Name of the Vulnerable Software and Affected Versions**
D-Link DIR-816 A2 version 1.10CNB04
**Description**
A critical issue has been found in the Web Interface component, specifically in the file /goform/setDeviceSettings. The manipulation of the `statuscheckpppoeuser` argument leads to os command injection. This can be exploited remotely.
**Recommendations**
For D-Link DIR-816 A2 version 1.10CNB04, as a temporary workaround, consider disabling access to the `/goform/setDeviceSettings` file until a patch is available. Restrict the use of the `statuscheckpppoeuser` argument in the Web Interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.