CVE-2019-10039: Critical severity d-link dir-816l firmware vulnerability
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dirlogin.asp and use an API URL /goform/setSysAdm to edit the web or system account without authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10039?
CVE-2019-10039 is a vulnerability in the D-Link DIR-816 A2 1.11 router that allows an attacker to edit the web or system account without authentication.
How severe is CVE-2019-10039?
CVE-2019-10039 has a severity rating of 9.8 (critical).
How can an attacker exploit CVE-2019-10039?
An attacker can exploit CVE-2019-10039 by obtaining the random token from dir_login.asp and using the API URL /goform/setSysAdm to edit the web or system account without authentication.
Which software versions are affected by CVE-2019-10039?
The D-Link DIR-816 A2 1.11 firmware is affected by CVE-2019-10039.
Is the D-Link DIR-816 A2 router vulnerable to CVE-2019-10039?
No, the D-Link DIR-816 A2 router is not vulnerable to CVE-2019-10039.