CVE-2021-26810: OS Command Injection
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dirsetWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26810?
CVE-2021-26810 is a remote code injection vulnerability that affects the D-link DIR-816 A2 v1.10 router firmware.
How does CVE-2021-26810 work?
CVE-2021-26810 allows an attacker to inject malicious code by manipulating an HTTP request parameter in the /goform/dir_setWanWifi handler function.
What is the severity of CVE-2021-26810?
CVE-2021-26810 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-26810?
D-link DIR-816 A2 v1.10b05 firmware is affected by CVE-2021-26810.
How can I fix CVE-2021-26810?
To fix CVE-2021-26810, update your D-link DIR-816 router firmware to a non-vulnerable version provided by D-link.