Dir 816
Vendor:
First CVE: Mar 25, 2019 · Active for 7 years
73
Total CVEs
More Total CVEs than 99% of tracked products
10.4
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dir 816 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2019
7 years ago
Most Recent CVE
May 11, 2026
74 days ago
CVE Severity & Scoring
Dir 81673 CVEs
25%
18%
58%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network73 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None72 (98.6%)
Unknown0 (0.0%)
Required1 (1.4%)
Privileges Required
Low9 (12.3%)
High0 (0.0%)
None64 (87.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37130CRITICAL In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced int | Aug 31, 2022 | 9.8 | 44 | NO | NO |
CVE-2022-37134CRITICAL D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stor | Aug 22, 2022 | 9.8 | 43 | NO | NO |
CVE-2021-27114CRITICAL An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fie | Apr 14, 2021 | 9.8 | 40 | NO | NO |
CVE-2024-57684CRITICAL An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted P | Jan 16, 2025 | 9.8 | 37 | NO | NO |
CVE-2022-36620HIGH D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting. | Aug 31, 2022 | 7.5 | 37 | NO | NO |
CVE-2022-29322CRITICAL D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip. | May 10, 2022 | 9.8 | 37 | NO | NO |
CVE-2025-5623CRITICAL A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulati | Jun 5, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-37128CRITICAL In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. | Aug 31, 2022 | 9.8 | 34 | NO | NO |
CVE-2026-8346HIGH A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in comman | May 11, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-8344HIGH A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulatio | May 11, 2026 | 8.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (73 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (73 CVEs).
Media Mentions
Signals from CVEs in this product scope (73 CVEs).
Top CNAs Publishing CVEs For Dir 816
Top CWEs
Versions
No cataloged versions.