PT-2026-25554 · D Link · Dir-816

Pjqwudi

·

Published

2026-03-02

·

Updated

2026-03-16

·

CVE-2026-4180

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-816 version 1.10CNB05
Description A flaw exists in D-Link DIR-816, specifically within the goahead component’s redirect.asp file. Manipulation of the token id argument can lead to improper access controls. This issue can be exploited remotely. The exploit is publicly available. This vulnerability affects products that are no longer supported by the maintainer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2026-04453
CVE-2026-4180

Affected Products

Dir-816