CVE-2019-10040: Critical severity d-link dir-816l firmware vulnerability
Published Mar 25, 2019
·Updated
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dirlogin.asp and use a hidden API URL /goform/SystemCommand to execute a system command without authentication.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.11
Dlink DIR-816=a2
Event History
Mar 25, 2019
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10040?
The severity of CVE-2019-10040 is critical with a score of 9.8.
2
What is the vulnerability description of CVE-2019-10040?
The vulnerability in D-Link DIR-816 A2 1.11 router allows an attacker to execute system commands without authentication.
3
How can an attacker exploit CVE-2019-10040?
An attacker can exploit CVE-2019-10040 by obtaining the random token from dir_login.asp and using the hidden API URL /goform/SystemCommand to execute system commands without authentication.
4
Which software versions are affected by CVE-2019-10040?
CVE-2019-10040 affects D-Link DIR-816 Firmware version 1.11.
5
Is D-Link DIR-816 A2 vulnerable to CVE-2019-10040?
No, D-Link DIR-816 A2 is not vulnerable to CVE-2019-10040.