CVE-2026-4181: D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow
A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4181?
CVE-2026-4181 is classified as a stack-based overflow vulnerability which poses significant security risks to affected systems.
How do I fix CVE-2026-4181?
To remediate CVE-2026-4181, update the D-Link DIR-816 firmware to the latest version released by D-Link.
Which devices are affected by CVE-2026-4181?
CVE-2026-4181 specifically affects the D-Link DIR-816 router running firmware version 1.10CNB05.
What are the potential consequences of exploiting CVE-2026-4181?
Exploitation of CVE-2026-4181 could allow attackers to execute arbitrary code, leading to full system compromise.
How can I determine if my D-Link DIR-816 is vulnerable to CVE-2026-4181?
Check the firmware version of your D-Link DIR-816; if it is 1.10CNB05 or earlier, the device is vulnerable to CVE-2026-4181.