ZeroHour

CVE-2024-13106

niche

Improper Access Control in D-Link DIR-816 IP QoS Handler

CVSS 4.0
6.9 medium
EPSS
27%p98
Published
()
Modified
AI analysis

CVE-2024-13106 is an improper access control flaw (CWE-266/CWE-284) in the IP QoS Handler of the D-Link DIR-816 A2 router, specifically in the /goform/form2IPQoSTcAdd handler. A remote attacker can send crafted requests to this endpoint without authentication (CVSS PR:N, UI:N) and manipulate the QoS handling logic in an unauthorized way. Per the CVSS 4.0 vector, the impact is limited to integrity: an attacker can make unauthorized changes (VI:L) with no direct confidentiality or availability impact, likely altering router QoS or related settings. Only D-Link DIR-816 A2 units running firmware 1.10CNB05_R1B011D88210 are identified as affected in the available data. The vulnerability is not yet listed in CISA KEV and no standalone PoC is catalogued, but the source description states an exploit has been publicly disclosed, and EPSS assigns a high 27.2% probability of exploitation within 30 days (98th percentile), so defenders should treat exploitation as plausible in the near term.

What to do: Check whether any internet-exposed D-Link DIR-816 A2 units run firmware 1.10CNB05_R1B011D88210 and upgrade to the latest firmware offered by D-Link for the A2 revision if a fix has been released (no fixed version is specified in the available data). Until patched, restrict the router's web management interface to the local network and avoid port-forwarding or remote-management exposure, since the flaw is exploitable remotely without authentication. Watch for the CVE's addition to CISA KEV or published PoCs given the high EPSS score.

Affected
D-Link DIR-816 A2 router (IP QoS Handler, /goform/form2IPQoSTcAdd)A2 hardware running firmware 1.10CNB05_R1B011D88210 (other firmware versions not specified in the available data)
Estimated exposure
nicheunknown precisely; likely on the order of tens of thousands of devices at most (single consumer router model, primarily Chinese-market firmware) — Estimate based on the DIR-816 A2 being a single, region-specific consumer router model (the CNB05 firmware designation indicates the Chinese-market variant) with no published active-install counts or internet-exposure scan totals available.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Vendors
dlink
Products
dir-816 firmware
Weakness
CWE-266, CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.