FAIL › dossier
dir-816
PRODUCT· dossier confidence 50%
D-Link's DIR-816 router exhibits a severe security posture, evidenced by two critical remote code execution and command injection vulnerabilities in its firmware. These flaws allow remote attackers to execute arbitrary code, indicating a pattern of insecure parameter handling and delayed patching in edge-device firmware.
PROFILE
Categorynetworking hardwareWhat they doD-Link DIR-816 is a wireless router manufactured by D-Link.
SECURITY POSTURE
The DIR-816 product line has a poor security track record, with multiple critical remote code execution and command injection vulnerabilities discovered in firmware versions prior to patching.
Notable failures
- CVE-2024-24321 critical RCE via wizardstep4_ssid_2 parameter
- CVE-2023-39637 critical command injection via /goform/Diagnosis component
Patterns: repeated unpatched critical RCEs in edge-device firmware; insecure parameter handling in web interfaces
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-02-08 | CVE-2024-24321 | critical | An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function. |
| 2023-09-12 | CVE-2023-39637 | critical | D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. |
Open questions: When were CVE-2024-24321 and CVE-2023-39637 patched? · What is the current firmware version of the DIR-816?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-21 04:03:03.545292+00:00