CVE-2026-4182: D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow
A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4182?
CVE-2026-4182 has been classified as a critical vulnerability due to its potential for remote code execution through stack-based buffer overflow.
How do I fix CVE-2026-4182?
To mitigate CVE-2026-4182, it is recommended to update the D-Link DIR-816 firmware to the latest version provided by D-Link.
What systems are affected by CVE-2026-4182?
The CVE-2026-4182 vulnerability affects the D-Link DIR-816 router running firmware version 1.10CNB05.
What type of vulnerability is CVE-2026-4182?
CVE-2026-4182 is a stack-based buffer overflow vulnerability that exploits the handling of parameters in the goahead web server.
Can CVE-2026-4182 be exploited remotely?
Yes, CVE-2026-4182 can be exploited remotely if an attacker manipulates affected parameters via the web interface of the D-Link DIR-816.