CVE-2024-57684: D-Link Dir-816 Firmware

Critical severity, CVSS 9.8. EPSS: 14.4% chance of exploitation in the next 30 days.

An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

Affected products

  • D-Link Dir-816 Firmware: version 1.10cnb05_r1b011d88210 only

Published 2025-01-16. Last modified 2026-06-17.