CVE-2018-17066: D-Link Dir-816 a2 Firmware

Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.

An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter.

Affected products

  • D-Link Dir-816 a2 Firmware: version 1.10_b05 only

Published 2018-09-15. Last modified 2026-06-17.