CVE-2026-8346: D-Link DIR-816 portForward command injection
A vulnerability was detected in D-Link DIR-816 1.10CNB05R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ipaddress results in command injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable WAN-side/remote management (administration from the Internet) on the device to prevent remote invocation of vulnerable portForward functionality.
D-Link DIR-816 remote_management = disabled - Configuration
Disable the port forwarding feature or remove any unnecessary port forwarding rules to avoid use of the vulnerable portForward function. If port forwarding is required, restrict rules to trusted internal hosts only.
D-Link DIR-816 port_forwarding = disabled - Compensating control
Block/deny WAN access to the router management interfaces (HTTP/HTTPS/SSH/Telnet) at the perimeter firewall or use ACLs to restrict management access to specific trusted IP addresses only.
- Compensating control
Isolate the affected device from the Internet (place on a segregated VLAN, behind an additional NAT/firewall, or take the device offline) until an official vendor fix is available and applied.
- Operational
Monitor device logs and network traffic for indicators of exploitation (unexpected port forwarding entries, unknown commands, or outbound connections). If compromise is suspected, disconnect the device from the network and perform a factory reset or device replacement.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8346?
CVE-2026-8346 is considered a high-severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-8346?
To fix CVE-2026-8346, update the D-Link DIR-816 router firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-8346?
CVE-2026-8346 affects users of the D-Link DIR-816 router with firmware version 1.10CNB05_R1B011D88210.
What can an attacker do with CVE-2026-8346?
An attacker can exploit CVE-2026-8346 to perform remote command injection through the portForward function.
Is there a workaround for CVE-2026-8346?
A potential workaround for CVE-2026-8346 is to disable remote management features until a firmware update is applied.