CVE-2026-4184Disclosure(dlink / dir-816)

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-816 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-816
  • dir-816_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-16)
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
dir-816dir-816_firmware

2 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-14: 1Mentions · 2026-03-15: 2Mentions · 2026-03-16: 3PoC Mentioned / Linked · 2026-03-15: 2Exploit Tool / Code · 2026-03-15: 2Exploit Tool / Code · 2026-03-16: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 203-1403-1503-16
Signal classification4 categories
Disclosure
233.3%
Exploit
233.3%
PoC
116.7%
General
116.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-141
Disclosure1
2026-03-152
Exploit1PoC1
2026-03-163
Disclosure1Exploit1General1
Full discourse6 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4184 - Critical A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Pe... https://www.thehackerwire.com/vulnerability/CVE-2026-4184/ https://t.co/k5sEmQwqhE

    Post summary

    The text announces a newly detected CVE‑2026‑4184 vulnerability in a D‑Link device, providing basic technical details but no PoC, exploit code, or patch information.

    0000045
    136 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4184: CRITICAL] Stack-based buffer overflow vulnerability detected in D-Link DIR-816 1.10CNB05. Exploit public and can be used remotely in unsupported products. #cybersecurity#cve,CVE-2026-4184,#cybersecurity https://cvefind.com/CVE-2026-4184

    Post summary

    The post announces CVE-2026-4184 as a critical stack-based buffer overflow in D-Link DIR‑816 and notes that a public exploit exists and can be used remotely, but it provides no PoC details, patches, or evidence of active exploitation.

    0000037
    601 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4184 A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the c… https://www.cve.org/CVERecord?id=CVE-2026-4184

    Post summary

    The post announces the discovery of CVE-2026-4184 in a D‑Link DIR‑816 router but provides no substantive technical details, proofs of exploitation, or mitigation information.

    00000143
    56.7K followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow CVE: CVE-2026-4184 PT-Identifier: PT-2026-25534 Vendor: D-link Product: DIR-816 CVSS: 9.3 Credits: pjqwudi (VulDB User) Description: A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4184 • https://vuldb.com/?id.351088 • https://vuldb.com/?ctiid.351088 • https://vuldb.com/?submit.769832 • https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_88/88.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    A publicly available exploit for CVE-2026-4184 is disclosed, targeting a stack-based buffer overflow on D-Link DIR-816, with detailed technical information and a GitHub PoC repository, but no evidence yet of active exploitation.

    0000096
    613 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-4184: D-Link DIR... Stack overflow in pskValue param on EOL D-Link DIR-816 routers - public exploit available for 9.3 CVSS remote code execution. #RCE #IoT #DLink. https://zerodaysignal.com/vulnerability/CVE-2026-4184 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑4184 reveals a stack overflow vulnerability in the pskValue parameter of EOL D-Link DIR‑816 routers, enabling remote code execution; a public exploit is available, but no active exploitation or patch is noted.

    00000100
    150 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for D-Link DIR-816 (CVE-2026-4184) https://vuldb.com/?id.351088

    Post summary

    A severe vulnerability (CVE-2026-4184) affecting D-Link DIR-816 has been disclosed. No PoC, exploit code, patch, or active exploitation details are provided in the text.

    0000086
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-816---
OSdlinkdir-816_firmware1.10cnb05--

Explore more