CVE-2017-6190: D-Link Dwr-116 Firmware

High severity, CVSS 7.5. EPSS: 18.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.

Affected products

  • D-Link Dwr-116 Firmware: version v1.00(cp)b10 only; version v1.01(eu) only; version v1.05(au) only

Published 2017-04-10. Last modified 2026-06-17.