Command Injection Vulnerability in D-Link DIR-816 Router
CVE-2026-8345
Key Information:
Badges
What is CVE-2026-8345?
A security vulnerability has been identified in the D-Link DIR-816 router, particularly within the function sub_445E7C located in /goform/singlePortForward. This vulnerability allows an attacker to manipulate the 'ip_address' argument, leading to remote command injection attacks. Due to its public disclosure, this exploit poses a significant risk to users who have not applied corrective measures. It is critical for administrators to promptly apply security updates to mitigate potential unauthorized access.
Affected Version(s)
DIR-816 1.10CNB05_R1B011D88210
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved