CVE-2021-39510: Command Injection
An issue was discovered in D-Link DIR816A1FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39510?
CVE-2021-39510 is a critical vulnerability discovered in the D-Link DIR816_A1_FW101CNB04 750m11ac wireless router that allows command injection through shell metacharacters in the user name.
How severe is CVE-2021-39510?
CVE-2021-39510 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2021-39510?
The D-Link DIR816_A1_FW101CNB04 750m11ac wireless router with firmware version 101cnb04 is affected by CVE-2021-39510.
How can CVE-2021-39510 be exploited?
CVE-2021-39510 can be exploited by constructing a user name string that contains shell metacharacters to perform command injection.
Are there any references for CVE-2021-39510?
Yes, you can find references for CVE-2021-39510 at the following links: [GitHub - doudoudedi/main-DIR-816_A1_Command-injection](https://github.com/doudoudedi/main-DIR-816_A1_Command-injection), [GitHub - doudoudedi/main-DIR-816_A1_Command-injection/blob/main/injection_A1.md](https://github.com/doudoudedi/main-DIR-816_A1_Command-injection/blob/main/injection_A1.md), [D-Link Security Bulletin](https://www.dlink.com/en/security-bulletin/)