CVE-2022-37123: OS Command Injection
D-link DIR-816 A2v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this D-link DIR-816 firmware vulnerability?
The vulnerability ID for this D-link DIR-816 firmware vulnerability is CVE-2022-37123.
What is the severity level of CVE-2022-37123?
The severity level of CVE-2022-37123 is high.
How can an attacker exploit the vulnerability in D-link DIR-816 firmware?
An attacker can exploit the vulnerability in D-link DIR-816 firmware by using command injection via the /goform/form2userconfig.cgi endpoint.
Is the D-link DIR-816 A2_v1.10CNB04.img firmware directly vulnerable to command injection?
Yes, the D-link DIR-816 A2_v1.10CNB04.img firmware is directly vulnerable to command injection via the /goform/form2userconfig.cgi endpoint.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [GitHub - Command injection via /goform/form2userconfig.cgi](https://github.com/z1r00/IOT_Vul/blob/main/dlink/Dir816/form2userconfig_cgi/readme.md) [D-Link Security Bulletin](https://www.dlink.com/en/security-bulletin/)