PT-2026-25554 · D Link · Dir-816
Pjqwudi
·
Published
2026-03-02
·
Updated
2026-03-16
·
CVE-2026-4180
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-816 version 1.10CNB05
Description
A flaw exists in D-Link DIR-816, specifically within the goahead component’s
redirect.asp file. Manipulation of the token id argument can lead to improper access controls. This issue can be exploited remotely. The exploit is publicly available. This vulnerability affects products that are no longer supported by the maintainer.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dir-816