CVE-2026-4182Disclosure(dlink / dir-816)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-816
  • dir-816_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-16)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dir-816dir-816_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-15: 1Mentions · 2026-03-16: 4PoC Mentioned / Linked · 2026-03-15: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 303-1503-16
Signal classification1 categories
Disclosure
5100.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-151
Disclosure1
2026-03-164
Disclosure4
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4182 - Critical A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of th... https://www.thehackerwire.com/vulnerability/CVE-2026-4182/ https://t.co/UJ0AchQuyz

    Post summary

    A new critical vulnerability was disclosed that affects a D-Link DIR‑816 router file, but no PoC, exploit, or patch information is provided.

    0000045
    136 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4182 - Critical A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of th... https://www.thehackerwire.com/vulnerability/CVE-2026-4182/ https://t.co/kfFapAA5Gx

    Post summary

    The text announces a CVE‑2026‑4182 vulnerability in D‑Link DIR‑816 routers, describing an affected file and component but providing no PoC, patch, or exploitation evidence.

    0000041
    136 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4182: CRITICAL] Vulnerability in D-Link DIR-816 1.10CNB05 discovered! Stack-based buffer overflow in goahead component's /goform/form2Wl5RepeaterStep2.cgi allows remote exploitation. Only affects uns...#cve,CVE-2026-4182,#cybersecurity https://cvefind.com/CVE-2026-4182

    Post summary

    The post announces a critical stack‑based buffer overflow in D‑Link DIR‑816 firmware, describing the affected component and remote exploitation possibility, but provides no PoC, patch, or evidence of active attacks.

    0000043
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4182 A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. Thi… https://www.cve.org/CVERecord?id=CVE-2026-4182

    Post summary

    The post announces CVE-2026-4182 as a weakness in D‑Link DIR‑816 affecting the /goform/form2Wl5RepeaterStep2.cgi file, but provides no details on exploitation, PoC, or remediation.

    00000162
    56.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow CVE: CVE-2026-4182 PT-Identifier: PT-2026-25556 Vendor: D-link Product: DIR-816 CVSS: 9.3 Credits: pjqwudi (VulDB User) Description: A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4182 • https://vuldb.com/?id.351086 • https://vuldb.com/?ctiid.351086 • https://vuldb.com/?submit.769830 • https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_86/86.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The text announces CVE‑2026‑4182 for D‑Link DIR‑816, detailing a stack‑based buffer overflow, high severity, and noting that a publicly available exploit exists.

    0000085
    613 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-816---
OSdlinkdir-816_firmware1.10cnb05--

Explore more