CVE-2024-13108: D-Link DIR-816 A2 form2NetSniper.cgi access control
Published Jan 2, 2025
·Updated
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
D-Link DIR-816 A2
All of the following
Dlink Dir-816 Firmware=1.10cnb05_r1b011d88210
Dlink DIR-816=a2
Event History
Jan 2, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13108?
CVE-2024-13108 has been declared as a critical vulnerability.
2
What vulnerabilities are present in CVE-2024-13108?
CVE-2024-13108 involves improper access controls affecting the /goform/form2NetSniper.cgi file.
3
How can CVE-2024-13108 be exploited?
CVE-2024-13108 can be exploited remotely, allowing attackers to manipulate the affected system.
4
How do I fix CVE-2024-13108?
To fix CVE-2024-13108, you should apply the latest firmware updates from D-Link for the DIR-816 A2 device.
5
What devices are affected by CVE-2024-13108?
CVE-2024-13108 affects the D-Link DIR-816 A2 router.