Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-10041 Details

Description

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form2userconfig.cgi to edit the system account without authentication.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-306Missing Authentication for Critical Function[email protected]

Affected Products

ProductVersions
dlink dir-816 firmware
1.11

CPE

  • cpe:2.3:o:dlink:dir-816_firmware:1.11:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
dlink dir-816
a2

CPE

  • cpe:2.3:h:dlink:dir-816:a2:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-10041
NVD Published Date:
Mar 25, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-10041 Details - Not Deferred