Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.1

CVE-2026-8345: D-Link DIR-816 Remote Command Injection Vulnerability

CVE-2026-8345
Summary

A vulnerability in the D-Link DIR-816 router's port forwarding feature allows an attacker to execute commands remotely, potentially giving them control over the device. This could lead to unauthorized access to your network or even allow the attacker to make changes to your router settings. To protect yourself, consider updating your router's firmware or replacing it if a fix is not available.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
dlink dir-816_firmware 1.10cnb05_r1b011d88210
cpe:2.3:o:dlink:dir-816_firmware:1.10cnb05_r1b011d88210:*:*:*:*:*:*:*
Original title
A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of th...
Original description
A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the argument ip_address leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
nvd CVSS2.0 6.5
nvd CVSS3.1 6.3
nvd CVSS4.0 2.1
Vulnerability type
CWE-74 Injection
CWE-77 Command Injection
Published: 11 May 2026 · Updated: 28 May 2026 · First seen: 11 May 2026