PT-2025-3538 · D Link · D-Link Dir-816 A2
Published
2024-12-30
·
Updated
2025-02-03
·
CVE-2024-57681
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link 816A2 FWv1.10CNB05 R1B011D88210
Description
An access control issue in the component form2alg.cgi of D-Link 816A2 FWv1.10CNB05 R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request to the "form2alg.cgi" endpoint, using a specially crafted HTTP POST request. This issue is related to insufficient access control in the form2alg.cgi script of the D-Link DIR-816A2 router's firmware.
Recommendations
As a temporary workaround, consider disabling the form2alg.cgi component until a patch is available.
Restrict access to the form2alg.cgi endpoint to minimize the risk of exploitation.
Avoid using the agl service in the affected device until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-816 A2