First published: Mon Aug 22 2022(Updated: )
D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is required, and reboot is executed when the function returns at the end.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-816 Firmware | =1.10cnb04 | |
Dlink DIR-816 | =a2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37133 is a vulnerability in D-link DIR-816 A2_v1.10CNB04.img firmware that allows unauthorized reboot of the router via /goform/doReboot without authentication.
CVE-2022-37133 has a severity rating of 7.5 out of 10 (high severity).
The D-link DIR-816 firmware version 1.10cnb04 is affected by CVE-2022-37133.
To fix CVE-2022-37133, update the D-link DIR-816 firmware to a version that is not vulnerable.
You can find more information about CVE-2022-37133 in the GitHub README file (https://github.com/z1r00/IOT_Vul/blob/main/dlink/Dir816/doReboot/readme.md) and the D-link security bulletin (https://www.dlink.com/en/security-bulletin/).