CVE-2024-13106
nicheImproper Access Control in D-Link DIR-816 IP QoS Handler
CVE-2024-13106 is an improper access control flaw (CWE-266/CWE-284) in the IP QoS Handler of the D-Link DIR-816 A2 router, specifically in the /goform/form2IPQoSTcAdd handler. A remote attacker can send crafted requests to this endpoint without authentication (CVSS PR:N, UI:N) and manipulate the QoS handling logic in an unauthorized way. Per the CVSS 4.0 vector, the impact is limited to integrity: an attacker can make unauthorized changes (VI:L) with no direct confidentiality or availability impact, likely altering router QoS or related settings. Only D-Link DIR-816 A2 units running firmware 1.10CNB05_R1B011D88210 are identified as affected in the available data. The vulnerability is not yet listed in CISA KEV and no standalone PoC is catalogued, but the source description states an exploit has been publicly disclosed, and EPSS assigns a high 27.2% probability of exploitation within 30 days (98th percentile), so defenders should treat exploitation as plausible in the near term.
What to do: Check whether any internet-exposed D-Link DIR-816 A2 units run firmware 1.10CNB05_R1B011D88210 and upgrade to the latest firmware offered by D-Link for the A2 revision if a fix has been released (no fixed version is specified in the available data). Until patched, restrict the router's web management interface to the local network and avoid port-forwarding or remote-management exposure, since the flaw is exploitable remotely without authentication. Watch for the CVE's addition to CISA KEV or published PoCs given the high EPSS score.
| D-Link DIR-816 A2 router (IP QoS Handler, /goform/form2IPQoSTcAdd) | A2 hardware running firmware 1.10CNB05_R1B011D88210 (other firmware versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/form2IPQoSTcAdd of the component IP QoS Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
- Vendors
- dlink
- Products
- dir-816 firmware
- Weakness
- CWE-266, CWE-284
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.