CVE Details
Basic Information
| Title | D-Link DIR-816 qosClassifier os command injection |
|---|---|
| Type | cve |
| Published | 2025-06-04T23:31:08.187Z |
| Last Seen |
Product Information
| Vendor | D-Link |
|---|---|
| Product | DIR-816 |
| Version | 1.10CNB05 |
CVSS Information
| Base Score | 6.9 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical vulnerability in D-Link DIR-816 1.10CNB05 allows remote attackers to execute arbitrary commands via the qosClassifier function, which is susceptible to OS command injection through the dip_address/sip_address parameters. The vulnerability is publicly disclosed and affects unsupported products. |
|---|---|
| AI Severity | High |
| Vendor | D-Link |
| Product | DIR-816 |
| Affected Version | 1.10CNB05 |
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-78, CWE-77 |
| Bulletin Family | |
| Source Data | D-Link DIR-816 1.10CNB05 |
Source Information
| Source Data | D-Link DIR-816 1.10CNB05 |
|---|---|
| Source Link |
Description
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score Summary
Base Score: 6.9 (MEDIUM)