Description
A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-05-11
Score: 5.3 Medium
EPSS: 5.0% Low
KEV: No
Impact: Command Injection
Action: Update Firmware
AI Analysis

Impact

The flaw is a command injection in the /goform/singlePortForward endpoint of the D‑Link DIR‑816 router firmware. By supplying a crafted ip_address value, an attacker can cause the device to execute arbitrary operating‑system commands through the web interface, potentially enabling remote compromise of the router.

Affected Systems

Vendor: D‑Link. Product: DIR‑816. Firmware: 1.10CNB05_R1B011D88210 is affected. No other versions are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 5% signifies a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that the attack may require management console access, but it could also be available to unauthenticated users if the interface is exposed.

Generated by OpenCVE AI on September 26, 2026 at 08:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the router firmware to a version that resolves the command‑injection issue.
  • If no update is available, disable the singlePortForward feature or block access to /goform/singlePortForward through the router's firewall or access control lists.
  • Restrict management access to the router’s internal network or enforce strong authentication to limit exposure.

Generated by OpenCVE AI on September 26, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-816
Dlink dir-816 Firmware
CPEs cpe:2.3:h:dlink:dir-816:a2:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-816_firmware:1.10cnb05_r1b011d88210:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-816
Dlink dir-816 Firmware

Tue, 12 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-816
Vendors & Products D-link
D-link dir-816

Mon, 11 May 2026 22:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Title D-Link DIR-816 singlePortForward sub_445E7C command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dir-816
Dlink Dir-816 Dir-816 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-12T13:20:15.688Z

Reserved: 2026-05-11T16:24:21.287Z

Link: CVE-2026-8345

cve-icon Vulnrichment

Updated: 2026-05-12T13:20:11.434Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-11T23:20:22.813

Modified: 2026-06-17T11:03:49.633

Link: CVE-2026-8345

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T08:45:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')