CVE-2021-39509
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 5.1%
from disclosure to weapon
Published on NVDAug 24
VulnCheck+1142d
exploitation probability
5.1%top 8% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
Affected products
n/a · n/a