FAIL › dossier
dir-816 firmware
PRODUCT· dossier confidence 20%
D-Link's networking hardware suffers from a chronic lack of secure firmware development, evidenced by multiple critical RCE and command injection vulnerabilities across its router product line. The company's track record shows a pattern of releasing patches only after vulnerabilities are publicly disclosed and exploited.
PROFILE
CategoryNetworking HardwareWhat they doD-Link manufactures networking hardware including routers and firmware for edge devices.
Websitehttps://www.dlink.com ↗
SECURITY POSTURE
D-Link exhibits a poor security posture with a history of critical remote code execution and denial-of-service vulnerabilities in its firmware and web interfaces, often requiring post-exploitation patches.
Notable failures
- CVE-2024-24321: Critical RCE via wizardstep4_ssid_2 parameter in DIR-816A2 firmware
- CVE-2023-39637: Critical command injection via /goform/Diagnosis in DIR-816 A2 firmware
- CVE-2026-71957: Critical buffer overflow in DWR-M961 app.cgi interface allowing arbitrary command execution
Patterns: repeated critical RCE and command injection flaws in firmware and web interfaces; unpatched edge-device vulnerabilities requiring post-exploitation patches
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-02-08 | CVE-2024-24321 | critical | An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function. |
| 2023-09-12 | CVE-2023-39637 | critical | D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. |
DOSSIER SOURCES
Open questions: D-Link's patch response timeline for CVE-2024-24321 · Whether CVE-2023-39637 was patched before public disclosure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:09:56.232089+00:00