CVE-2019-16190: D-Link Dir-868l Firmware

Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.

SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or category_view.php.

Affected products

  • D-Link Dir-868l Firmware: up to and including 2.03
  • D-Link Dir-885l Firmware: up to and including 1.20
  • D-Link Dir-895l Firmware: up to and including 1.21

Published 2019-09-09. Last modified 2026-06-17.