PT-2026-39870 · D Link · Dir-816

Stksgg

·

Published

2026-05-11

·

Updated

2026-05-12

·

CVE-2026-8346

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-816 version 1.10CNB05 R1B011D88210
Description A remote command injection issue exists in the portForward() function. By manipulating the ip address argument, an attacker can execute arbitrary commands on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the portForward() function to minimize the risk of exploitation.

Exploit

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-8346

Affected Products

Dir-816