CVE-2026-4181General(dlink / dir-816)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-816 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-816
  • dir-816_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-16)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
dir-816dir-816_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-15: 1Mentions · 2026-03-16: 3PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-03-15: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 103-1503-16
Signal classification3 categories
General
250.0%
Exploit
125.0%
PoC
125.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-151
Exploit1
2026-03-163
General2PoC1
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-4181 A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. T… https://www.cve.org/CVERecord?id=CVE-2026-4181

    Post summary

    The statement announces a newly discovered vulnerability in D‑Link DIR‑816 with minimal technical details and no further information about exploits or mitigations.

    00010159
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-4181 - Critical A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of t... https://www.thehackerwire.com/vulnerability/CVE-2026-4181/ https://t.co/7pYfgiV4W7

    Post summary

    The post announces a critical flaw in a D‑Link router but provides minimal technical detail, no evidence of exploitation, and no mitigation information.

    0000055
    136 followersView on X
  • CVEFind.com@CveFindCom
    PoC

    [CVE-2026-4181: CRITICAL] Security flaw in D-Link DIR-816 1.10CNB05 discovered - stack-based buffer overflow in /goform/form2RepeaterStep2.cgi component. Exploit released, affects unsupported products.#cve,CVE-2026-4181,#cybersecurity https://cvefind.com/CVE-2026-4181

    Post summary

    A critical stack-based buffer overflow was identified in the D-Link DIR-816 firmware, with an exploit released, though no patch or signs of active exploitation are reported.

    0000042
    601 followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow CVE: CVE-2026-4181 PT-Identifier: PT-2026-25555 Vendor: D-link Product: DIR-816 CVSS: 9.3 Credits: pjqwudi (VulDB User) Description: A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4181 • https://vuldb.com/?id.351085 • https://vuldb.com/?ctiid.351085 • https://vuldb.com/?submit.769829 • https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_85/85.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    CVE-2026-4181 is a stack-based buffer overflow in D-Link DIR-816's form2RepeaterStep2.cgi; publicly available exploit code exists, but there is no evidence of current active exploitation and no patch is mentioned.

    00000100
    613 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-816---
OSdlinkdir-816_firmware1.10cnb05--

Explore more