CVE-2026-4180

7.3

D-Link · DIR-816

An unauthenticated access control vulnerability in the D-Link DIR-816 goahead component allows attackers to retrieve token IDs via redirect.asp, enabling full unauthorized device configuration.

Executive summary

A critical, unauthenticated access control vulnerability in the D-Link DIR-816 router allows remote attackers to bypass authentication and modify device configurations.

Vulnerability

This vulnerability involves improper access controls within the goahead component, specifically the redirect.asp file. An unauthenticated remote attacker can access this file to obtain valid authentication tokens, which allows them to bypass security controls and perform unauthorized administrative actions, such as resetting Wi-Fi credentials.

Business impact

Successful exploitation of this vulnerability results in a total compromise of the affected router's management and wireless security. Because the device is end-of-life and unsupported by the vendor, there is no path for official security patches, leaving the device permanently exposed to unauthorized configuration changes and potential lateral movement within the network. With a CVSS score of 7.3, this represents a high-risk scenario for any environment still utilizing this hardware.

Remediation

Immediate Action: As this product is no longer supported by D-Link and no patch is available, the immediate recommendation is to decommission and replace the affected device with a currently supported router.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at the router's management interface, particularly requests targeting the redirect.asp endpoint.

Compensating Controls: If immediate replacement is not feasible, isolate the router from the public internet using a robust firewall and restrict management access to a dedicated, secure local management VLAN.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the research write-up provided by Jiaqian Peng.

Analyst recommendation

The D-Link DIR-816 is confirmed to be end-of-life and contains a critical, unauthenticated vulnerability for which no vendor fix will be provided. Organizations must treat these devices as inherently compromised if they remain exposed to the network. We strongly recommend immediate retirement and replacement of all units to mitigate the risk of unauthorized network access and potential data exfiltration.

More D-Link CVEs

Sources

Originally found and disclosed by pjqwudi (VulDB User), per the CVE Program record.