CVE-2026-8344: D-Link DIR-816 formDMZ.cgi sub_445E7C command injection
A weakness has been identified in D-Link DIR-816 1.10CNB05R1B011D88210. Affected by this vulnerability is the function sub445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the DMZ feature in the router's administration interface to avoid invoking /goform/formDMZ.cgi (which contains the vulnerable sub_445E7C).
D-Link DIR-816 (web administration) DMZ = disabled - Configuration
Disable remote/WAN-side management access to prevent remote initiation of the command injection vulnerability in formDMZ.cgi.
D-Link DIR-816 (remote administration) remote_management = disabled - Compensating control
Block or restrict access to the router's management interfaces (HTTP/HTTPS/administration ports) from untrusted networks at the network perimeter. Allow access only from trusted IP addresses or management VLANs, or isolate the device from the internet until a vendor fix is available.
- Operational
If exploitation is suspected, disconnect the device from networks, perform recovery actions such as factory reset/reflash with vendor-supplied firmware, and change administrative credentials. Monitor for signs of compromise and apply vendor updates when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8344?
CVE-2026-8344 is classified as a high severity vulnerability due to its potential for remote command injection.
How does CVE-2026-8344 affect the D-Link DIR-816?
CVE-2026-8344 affects the D-Link DIR-816 version 1.10CNB05_R1B011D88210 by allowing remote attackers to execute arbitrary commands.
Is there a patch available for CVE-2026-8344?
Currently, a patch for CVE-2026-8344 has not been officially released by D-Link.
What are the risks related to CVE-2026-8344?
The risks of CVE-2026-8344 include unauthorized remote access and control over affected devices.
How can I mitigate the risks associated with CVE-2026-8344?
Mitigating the risks of CVE-2026-8344 involves disabling remote administration features and monitoring device logs for unusual activities.