CVE-2026-4184

A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_88/88.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.351088 Permissions Required VDB Entry
https://vuldb.com/?id.351088 Third Party Advisory VDB Entry
https://vuldb.com/?submit.769832 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-816_firmware:1.10cnb05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-816:-:*:*:*:*:*:*:*

History

19 Mar 2026, 19:20

Type Values Removed Values Added
First Time Dlink dir-816 Firmware
Dlink dir-816
Dlink
CWE CWE-787
Summary
  • (es) Una vulnerabilidad fue detectada en D-Link DIR-816 1.10CNB05. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /goform/form2Wl5BasicSetup.cgi del componente goahead. Realizar una manipulación del argumento pskValue resulta en desbordamiento de búfer basado en pila. El ataque es posible de ser llevado a cabo remotamente. El exploit es ahora público y puede ser usado. Esta vulnerabilidad solo afecta productos que ya no son soportados por el mantenedor.
CPE cpe:2.3:o:dlink:dir-816_firmware:1.10cnb05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-816:-:*:*:*:*:*:*:*
References () https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_88/88.md - () https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_88/88.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.351088 - () https://vuldb.com/?ctiid.351088 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.351088 - () https://vuldb.com/?id.351088 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.769832 - () https://vuldb.com/?submit.769832 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-03-19 19:20


NVD link : CVE-2026-4184

Mitre link : CVE-2026-4184

CVE.ORG link : CVE-2026-4184


JSON object : View

Products Affected

dlink

  • dir-816
  • dir-816_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write