CVE-2018-20305: D-Link Dir-816 a2 Firmware

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

D-Link DIR-816 A2 1.10 B05 devices allow arbitrary remote code execution without authentication via the newpass parameter. In the /goform/form2userconfig.cgi handler function, a long password may lead to a stack-based buffer overflow and overwrite a return address.

Affected products

  • D-Link Dir-816 a2 Firmware: version 1.10b05 only

Published 2018-12-20. Last modified 2026-06-17.