CVE-2019-10042 describes an authentication bypass vulnerability in D-Link DIR-816 A2 1.11 routers, allowing an unauthenticated attacker to reset the device to factory defaults. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and requires no user interaction, as an attacker can obtain a required token from a publicly accessible page and then use a specific API endpoint. While there is no evidence of active exploitation, nor publicly available exploit code in common repositories, the vulnerability's nature poses a significant risk for affected devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.11CPE matchmatch criteria | cpe:2.3:o:dlink:dir-816_firmware:1.11:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.