CVE-2026-8346: D-Link DIR-816 portForward command injection
A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8346?
CVE-2026-8346 is considered a high-severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-8346?
To fix CVE-2026-8346, update the D-Link DIR-816 router firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-8346?
CVE-2026-8346 affects users of the D-Link DIR-816 router with firmware version 1.10CNB05_R1B011D88210.
What can an attacker do with CVE-2026-8346?
An attacker can exploit CVE-2026-8346 to perform remote command injection through the portForward function.
Is there a workaround for CVE-2026-8346?
A potential workaround for CVE-2026-8346 is to disable remote management features until a firmware update is applied.