Dir 816l
Vendor:
First CVE: Nov 18, 2015 · Active for 10 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dir 816l over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2015
10 years ago
Most Recent CVE
Nov 15, 2025
253 days ago
CVE Severity & Scoring
Dir 816l15 CVEs
27%
33%
40%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (93.3%)
Unknown1 (6.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (93.3%)
High0 (0.0%)
Unknown1 (6.7%)
User Interaction
None12 (80.0%)
Unknown1 (6.7%)
Required2 (13.3%)
Privileges Required
Low2 (13.3%)
High0 (0.0%)
None12 (80.0%)
Unknown1 (6.7%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28955HIGH An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php. | May 18, 2022 | 7.5 | 56 | NO | YES |
CVE-2020-15893CRITICAL An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command inje | Jul 22, 2020 | 9.8 | 53 | NO | YES |
CVE-2022-28956CRITICAL An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payload. | May 18, 2022 | 9.8 | 42 | NO | NO |
CVE-2025-9727CRITICAL A weakness has been identified in D-Link DIR-816L 206b01. Affected by this issue is the function soapcgi_main of the file /soap.cgi. This manipulation of the argument service cause | Aug 31, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-13189CRITICAL A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID le | Nov 15, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-13188CRITICAL A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing man | Nov 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13191CRITICAL A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the file /soap.cgi. This manipulation causes stack-based buffer ove | Nov 15, 2025 | 9.8 | 32 | NO | NO |
CVE-2020-15895MEDIUM An XSS issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. In the file webinc/js/info.php, no output filtration is applied to the RESULT parameter, before it' | Jul 22, 2020 | 6.1 | 32 | NO | YES |
CVE-2025-13190HIGH A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the file /portal/__ajax_exporer.sgi. The manipulation of the arg | Nov 15, 2025 | 8.8 | 29 | NO | NO |
CVE-2015-5999MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentica | Nov 18, 2015 | 6.8 | 27 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Dir 816l
Top CWEs
Versions
No cataloged versions.