CRITICAL🇵🇱 Wersja polska

CVE-2025-5622

CVSS 9.3v4.0pub. 2025-06-05upd. 2025-06-06

A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

🤖 AI Analysis
How it works

The vulnerability affects the wirelessApcli_5g function handled by the /goform/wirelessApcli_5g endpoint. Manipulation of the apcli_mode_5g, apcli_enc_5g, or apcli_default_key_5g parameters causes a stack-based buffer overflow — user-supplied data is copied to a stack buffer without proper length verification. The attack can be conducted remotely over the network, and the exploit has been publicly disclosed and may be actively exploited.

Impact

An attacker can achieve arbitrary code execution on the device (RCE), gain complete control over the router, or cause it to crash. Due to the lack of authentication requirements, this vulnerability poses a serious threat to all devices accessible from the network.

Mitigation & patch

D-Link has not issued and does not plan to issue a patch, as the product has reached End-of-Life status. It is recommended to immediately remove the device from service and replace it with an actively supported model. As interim measures, restrict access to the administrative interface only to trusted local networks and disable remote management on the device.

Who is affected

D-Link DIR-816 with firmware version 1.10CNB05. The device is no longer supported by the manufacturer.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dir 816

    HW
    Dlink
    all versions
  • Dlink Dir 816 Firmware

    OS
    Dlink
    1.10cnb05
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2025-45931CRITICAL9.8PL ✓same product

RCE w D-Link DIR-816-A2 przez podatną funkcję system() w goahead

CVE-2025-5630CRITICAL9.3PL ✓same product

D-Link DIR-816: Stack-based buffer overflow w /goform/form2lansetup.cgi

CVE-2025-5623CRITICAL9.3PL ✓same product

Stack-based buffer overflow w D-Link DIR-816 – funkcja qosClassifier

CVE-2025-5624CRITICAL9.3PL ✓same product

Stack-based buffer overflow w D-Link DIR-816 — funkcja QoSPortSetup

CVE-2024-57684CRITICAL9.8PL ✓same product

D-Link DIR-816: nieautoryzowana zmiana konfiguracji DMZ przez formDMZ.cgi