Impact
The vulnerability is a command injection in the sub_445E7C function of the /goform/singlePortForward endpoint in D‑Link DIR‑816 firmware 1.10CNB05_R1B011D88210. The unvalidated ip_address argument permits injection of operating‑system commands via the web interface, leading to arbitrary code execution on the device. This flaw represents both a missing input validation weakness (CWE‑74) and an OS command injection (CWE‑77), compromising the confidentiality, integrity, and availability of the network traffic managed by the router.
Affected Systems
Vendor: D‑Link. Product: DIR‑816. Affected firmware: 1.10CNB05_R1B011D88210. No other versions are specified.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Public disclosure confirms that attackers can manipulate the ip_address parameter to /goform/singlePortForward over the router's web interface, allowing remote command execution. The description does not state whether authentication is required, so it is inferred that the attack may require access to the management interface but this detail is not specified. These conditions make the vulnerability significant for exposed or poorly secured routers.
OpenCVE Enrichment