Description
A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-05-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection in the sub_445E7C function of the /goform/singlePortForward endpoint in D‑Link DIR‑816 firmware 1.10CNB05_R1B011D88210. The unvalidated ip_address argument permits injection of operating‑system commands via the web interface, leading to arbitrary code execution on the device. This flaw represents both a missing input validation weakness (CWE‑74) and an OS command injection (CWE‑77), compromising the confidentiality, integrity, and availability of the network traffic managed by the router.

Affected Systems

Vendor: D‑Link. Product: DIR‑816. Affected firmware: 1.10CNB05_R1B011D88210. No other versions are specified.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Public disclosure confirms that attackers can manipulate the ip_address parameter to /goform/singlePortForward over the router's web interface, allowing remote command execution. The description does not state whether authentication is required, so it is inferred that the attack may require access to the management interface but this detail is not specified. These conditions make the vulnerability significant for exposed or poorly secured routers.

Generated by OpenCVE AI on May 12, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest version that fixes the command injection.
  • If no update is available, disable the singlePortForward feature or block access to /goform/singlePortForward via firewall or router access‑control lists.
  • Restrict management access to the router to the internal network only or enforce strong authentication.

Generated by OpenCVE AI on May 12, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-816
Dlink dir-816 Firmware
CPEs cpe:2.3:h:dlink:dir-816:a2:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-816_firmware:1.10cnb05_r1b011d88210:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-816
Dlink dir-816 Firmware

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-816
Vendors & Products D-link
D-link dir-816

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Title D-Link DIR-816 singlePortForward sub_445E7C command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dir-816
Dlink Dir-816 Dir-816 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-12T13:20:15.688Z

Reserved: 2026-05-11T16:24:21.287Z

Link: CVE-2026-8345

cve-icon Vulnrichment

Updated: 2026-05-12T13:20:11.434Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T23:20:22.813

Modified: 2026-05-12T19:55:38.630

Link: CVE-2026-8345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T00:30:04Z

Weaknesses