Impact
The flaw is a command injection in the /goform/singlePortForward endpoint of the D‑Link DIR‑816 router firmware. By supplying a crafted ip_address value, an attacker can cause the device to execute arbitrary operating‑system commands through the web interface, potentially enabling remote compromise of the router.
Affected Systems
Vendor: D‑Link. Product: DIR‑816. Firmware: 1.10CNB05_R1B011D88210 is affected. No other versions are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 5% signifies a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that the attack may require management console access, but it could also be available to unauthenticated users if the interface is exposed.
OpenCVE Enrichment