CVE-2019-10041: Critical severity d-link dir-816l firmware vulnerability
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dirlogin.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10041?
CVE-2019-10041 is a vulnerability found in the D-Link DIR-816 A2 1.11 router that allows an attacker to edit the system account without authentication.
How severe is CVE-2019-10041?
CVE-2019-10041 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2019-10041?
An attacker can exploit CVE-2019-10041 by obtaining the random token from dir_login.asp and using an API URL to edit the system account without authentication.
Which software versions are affected by CVE-2019-10041?
The D-Link DIR-816 A2 firmware version 1.11 is affected by CVE-2019-10041.
Is the D-Link DIR-816 A2 vulnerable to CVE-2019-10041?
Yes, the D-Link DIR-816 A2 is vulnerable to CVE-2019-10041.