CVE-2019-7642: D-Link Dir-816 Firmware

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain users' DNS query logs and login logs. Vulnerable targets include but are not limited to the latest firmware versions of DIR-817LW (A1-1.04), DIR-816L (B1-2.06), DIR-816 (B1-2.06?), DIR-850L (A1-1.09), and DIR-868L (A1-1.10).

Affected products

  • D-Link Dir-816 Firmware: version 2.06 only
  • D-Link Dir-816l Firmware: version 2.06 only
  • D-Link Dir-817lw Firmware: version 1.04 only
  • D-Link Dir-850l Firmware: version 1.09 only
  • D-Link Dir-868l Firmware: version 1.10 only

Published 2019-03-25. Last modified 2026-06-17.