Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Critical

Stack-based buffer overflow in D-Link dws/api/Login session cookie handling

IdentifiersCVE-2016-5681CWE-121

CVE-2016-5681 is a stack-based buffer overflow in the dws/api/Login component of multiple D-Link router models. According to the provided content, the flaw is triggered when the device processes an overly long session cookie, causing a stack overwrite in the login handling path. A remote attacker can send a crafted request containing the long session cookie to the vulnerable endpoint and potentially achieve arbitrary code execution on the router. Affected devices include D-Link DIR-850L B1 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 before 3.01WWb02, DIR-823 A1 before 1.00WWb05, DIR-895L A1 before 1.11WWb04, DIR-890L A1 before 1.09b14, DIR-885L A1 before 1.11WWb07, DIR-880L A1 before 1.07WWb08, DIR-868L B1 before 2.03WWb01, and DIR-868L C1 before 3.00WWb01.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow remote arbitrary code execution on the affected router. In practice, this can give an attacker control of the device in the router's execution context, enabling malware deployment, persistence, traffic interception or redirection, configuration changes, use of the device as a proxy or scanning node, and follow-on compromise of the surrounding network.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching or replacement is not possible, disable remote administration and prevent untrusted network access to the management interface and affected web endpoints, including dws/api/Login. Restrict management access to trusted internal hosts or a dedicated management network, block WAN exposure with firewall rules, monitor for anomalous HTTP requests containing oversized Cookie headers or session values, and retire unsupported/end-of-life routers that no longer receive security updates.

Remediation

Patch, then assume compromise.

Upgrade affected D-Link devices to fixed firmware versions or later where available. The provided content identifies the following fixed baselines: DIR-850L B1 2.07WWB05, DIR-818LW Bx 2.05b03beta03, DIR-822 C1 3.01WWb02, DIR-823 A1 1.00WWb05, DIR-895L A1 1.11WWb04, DIR-890L A1 1.09b14, DIR-885L A1 1.11WWb07, DIR-880L A1 1.07WWb08, DIR-868L B1 2.03WWb01, and DIR-868L C1 3.00WWb01. Devices listed without a fixed version in the provided content should be checked against vendor guidance. If the hardware is end-of-life and no supported firmware is available, replace the device.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
D-LinkDir-817l(W) Firmwareoperating_system
D-LinkDir-818l(W) Firmwareoperating_system
D-LinkDir-822 Firmwareoperating_system
D-LinkDir-823 Firmwareoperating_system
D-LinkDir-850l Firmareoperating_system
D-LinkDir-868l Firmwareoperating_system
D-LinkDir-880l Firmwareoperating_system
D-LinkDir-885l Firmwareoperating_system
D-LinkDir-890l Firmwareoperating_system
D-LinkDir-895l Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware8

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.