# CVE-2026-4182

## Summary

- **CVE ID:** CVE-2026-4182
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-121, CWE-119
- **Published:** Mar 15, 2026
- **Last Modified:** Mar 16, 2026

## Description

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

## Affected Products

- D-Link — DIR-816 (1.10CNB05)

## References

- [CNA](https://vuldb.com/?id.351086)
- [CNA](https://vuldb.com/?ctiid.351086)
- [CNA](https://vuldb.com/?submit.769830)
- [CNA](https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_86/86.md)
- [CNA](https://www.dlink.com/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.08%
- **EPSS Percentile:** 62.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._