CVE-2021-31326: Critical severity d-link dir-816l firmware vulnerability
Published Mar 23, 2022
·Updated
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10cnb05
Dlink DIR-816=a2
Event History
Mar 23, 2022
CVE Published
via MITRE·11:24 PM
Data Sourced
via MITRE·11:24 PM
Description
Frequently Asked Questions
1
What is CVE-2021-31326?
CVE-2021-31326 is a vulnerability that allows unauthenticated attackers to arbitrarily reset the D-Link DIR-816 A2 1.10 B05 device.
2
How severe is CVE-2021-31326?
CVE-2021-31326 has a severity level of critical with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2021-31326?
The D-Link DIR-816 firmware version 1.10cnb05 is affected by CVE-2021-31326.
4
How can the device be reset by an attacker using CVE-2021-31326?
An attacker can reset the device by sending a crafted tokenid parameter to /goform/form2Reboot.cgi.
5
Are all D-Link DIR-816 devices vulnerable to CVE-2021-31326?
No, only the D-Link DIR-816 A2 devices with firmware version 1.10cnb05 are vulnerable to CVE-2021-31326.