CVSS v3
9.8
CRITICAL
EPSS Score
16.3%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function. This can lead to command injection through shell metacharacters.
Active exploitation of CVE-2021-39509 has not been confirmed. The EPSS score is 16.3%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2021-39509 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).