Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.1

CVE-2026-8344: D-Link DIR-816 Router Command Injection Vulnerability

CVE-2026-8344
Summary

A weakness in the D-Link DIR-816 router's configuration page allows an attacker to inject malicious commands remotely, potentially taking control of the router. This vulnerability has been made public and could be exploited by attackers. To protect your network, update your router's firmware to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dlink dir-816_firmware 1.10cnb05_r1b011d88210
cpe:2.3:o:dlink:dir-816_firmware:1.10cnb05_r1b011d88210:*:*:*:*:*:*:*
Original title
A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command ...
Original description
A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
nvd CVSS2.0 6.5
nvd CVSS3.1 6.3
nvd CVSS4.0 2.1
Vulnerability type
CWE-74 Injection
CWE-77 Command Injection
Published: 11 May 2026 · Updated: 28 May 2026 · First seen: 11 May 2026