CVE-2026-4183Disclosure(dlink / dir-816)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-816 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-816
  • dir-816_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-16)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dir-816dir-816_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-15: 2Mentions · 2026-03-16: 3PoC Mentioned / Linked · 2026-03-15: 2PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-03-15: 2Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 203-1503-16
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
General
120.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-152
Disclosure1Exploit1
2026-03-163
Disclosure2General1
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4183 - Critical A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulat... https://www.thehackerwire.com/vulnerability/CVE-2026-4183/ https://t.co/U25IxYTsnp

    Post summary

    The brief notice announces a critical CVE-2026-4183 vulnerability in a D‑Link router’s form handler, providing minimal technical specifics but no PoC, exploit, patch, or evidence of active exploitation.

    0000037
    136 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4183: CRITICAL] Security alert: Vulnerability found in D-Link DIR-816 1.10CNB05 allows remote stack-based buffer overflow. Exploit publicly available for unsupported products.#cve,CVE-2026-4183,#cybersecurity https://cvefind.com/CVE-2026-4183

    Post summary

    A critical stack-based buffer overflow vulnerability (CVE-2026-4183) was disclosed in D-Link DIR‑816 routers, with a publicly available exploit for unsupported firmware, but no active exploitation or patch information was provided.

    0000048
    601 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4183 A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goa… https://www.cve.org/CVERecord?id=CVE-2026-4183

    Post summary

    The entry simply announces the existence of CVE‑2026‑4183 with minimal descriptive details and no evidence of PoC, exploit, active usage, or mitigation.

    00000157
    56.7K followersView on X
  • dbugs@ptdbugs
    Disclosure

    D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow CVE: CVE-2026-4183 Vendor: D-link Product: DIR-816 CVSS: 9.3 Credits: pjqwudi (VulDB User) Description: A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4183 • https://vuldb.com/?id.351087 • https://vuldb.com/?ctiid.351087 • https://vuldb.com/?submit.769831 • https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_87/87.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The post announces CVE‑2026‑4183, a high‑severity stack‑based buffer overflow in D‑Link DIR‑816, provides PoC links, and notes that the exploit is publicly disclosed.

    0000074
    613 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-4183: D-Link DIR-816 goahead form2WlanB... Remote stack smash in abandoned D-Link DIR-816 via pskValue param - public exploit drops you straight into RCE on 9.3 CV... https://zerodaysignal.com/vulnerability/CVE-2026-4183 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-4183 is a remote stack‑smash vulnerability in D‑Link DIR‑816 that can be exploited via the pskValue parameter to achieve remote code execution; a public exploit is available.

    0000081
    150 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-816---
OSdlinkdir-816_firmware1.10cnb05--

Explore more