CVE-2022-37128: Critical severity d-link dir-816l firmware vulnerability
Published Aug 31, 2022
·Updated
In D-Link DIR-816 A2v1.10CNB04.img the network can be initialized without authentication via /goform/wizardend.
Affected Software
2 affected components
Dlink Dir-816 Firmware=1.10cnb04
Dlink DIR-816=a2
Event History
Aug 31, 2022
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-37128.
2
What is the severity of CVE-2022-37128?
The severity of CVE-2022-37128 is critical, with a severity value of 9.8.
3
What software is affected by CVE-2022-37128?
The D-Link DIR-816 firmware version 1.10cnb04 is affected by CVE-2022-37128.
4
How can the network be initialized without authentication?
The network can be initialized without authentication via /goform/wizard_end.
5
How to fix CVE-2022-37128?
There is currently no known fix or patch available for CVE-2022-37128. It is recommended to follow the vendor's security bulletin for updates and mitigation instructions.