CVE-2022-37133: High severity d-link dir-816l firmware vulnerability
D-link DIR-816 A2v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37133?
CVE-2022-37133 is a vulnerability in D-link DIR-816 A2_v1.10CNB04.img firmware that allows unauthorized reboot of the router via /goform/doReboot without authentication.
How severe is CVE-2022-37133?
CVE-2022-37133 has a severity rating of 7.5 out of 10 (high severity).
Which software versions are affected by CVE-2022-37133?
The D-link DIR-816 firmware version 1.10cnb04 is affected by CVE-2022-37133.
How can I fix CVE-2022-37133?
To fix CVE-2022-37133, update the D-link DIR-816 firmware to a version that is not vulnerable.
Where can I find more information about CVE-2022-37133?
You can find more information about CVE-2022-37133 in the GitHub README file (https://github.com/z1r00/IOT_Vul/blob/main/dlink/Dir816/doReboot/readme.md) and the D-link security bulletin (https://www.dlink.com/en/security-bulletin/).