PatchSiren cyber security CVE debrief
CVE-2016-10181 Dlink CVE debrief
CVE-2016-10181 is an information disclosure issue in the D-Link DWR-932B router: requests to qmiweb with CfgType=get_homeCfg can expose sensitive information. NVD rates the issue HIGH (CVSS 7.5) because it is network-reachable, requires no authentication or user interaction, and can disclose high-confidentiality data.
- Vendor
- Dlink
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-30
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-30
- Advisory updated
- 2026-05-13
Who should care
Administrators and owners of D-Link DWR-932B routers, especially systems matching the affected firmware CPE, and security teams responsible for exposed consumer or small-office LTE routers.
Technical summary
NVD maps the affected software to cpe:2.3:o:dlink:dwr-932b_firmware:02.02eu:revb. The issue is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The CVE description states that qmiweb provides sensitive information for CfgType=get_homeCfg requests. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a remotely reachable disclosure with no integrity or availability impact documented.
Defensive priority
High. This is a network-exposed information disclosure flaw with no authentication requirement and high confidentiality impact. Prioritize it for any Internet-facing or broadly accessible D-Link DWR-932B deployment.
Recommended defensive actions
- Identify D-Link DWR-932B devices in inventory and verify whether the affected firmware version is deployed.
- Restrict or remove network exposure of management interfaces and related services where possible.
- Apply vendor-provided firmware updates or mitigations if available; if no fix is available, isolate or replace affected devices.
- Review logs and access controls for unexpected requests related to qmiweb or CfgType=get_homeCfg.
- Treat any data exposed through the affected request path as sensitive and rotate credentials or secrets if exposure is suspected.
Evidence notes
The supplied corpus includes the CVE record, NVD detail data, and a third-party technical advisory reference. NVD lists the vulnerability as modified on 2026-05-13, while the CVE itself was published on 2017-01-30; the modified date applies to the record, not the original vulnerability disclosure. No KEV listing is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-10181 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-10181
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-10181 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10181
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://pierrekim.github.io/blog/2016-09-28-dlink-dwr-932b-lte-routers-vulnerabilities.html
[email protected] - Exploit, Technical Description, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.