CVE-2019-10042: D-Link Dir-816 Firmware

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/LoadDefaultSettings to reset the router without authentication.

Affected products

  • D-Link Dir-816 Firmware: version 1.11 only

Published 2019-03-25. Last modified 2026-06-17.