PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-10181 Dlink CVE debrief

CVE-2016-10181 is an information disclosure issue in the D-Link DWR-932B router: requests to qmiweb with CfgType=get_homeCfg can expose sensitive information. NVD rates the issue HIGH (CVSS 7.5) because it is network-reachable, requires no authentication or user interaction, and can disclose high-confidentiality data.

Vendor
Dlink
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-30
Original CVE updated
2026-05-13
Advisory published
2017-01-30
Advisory updated
2026-05-13

Who should care

Administrators and owners of D-Link DWR-932B routers, especially systems matching the affected firmware CPE, and security teams responsible for exposed consumer or small-office LTE routers.

Technical summary

NVD maps the affected software to cpe:2.3:o:dlink:dwr-932b_firmware:02.02eu:revb. The issue is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The CVE description states that qmiweb provides sensitive information for CfgType=get_homeCfg requests. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating a remotely reachable disclosure with no integrity or availability impact documented.

Defensive priority

High. This is a network-exposed information disclosure flaw with no authentication requirement and high confidentiality impact. Prioritize it for any Internet-facing or broadly accessible D-Link DWR-932B deployment.

Recommended defensive actions

  • Identify D-Link DWR-932B devices in inventory and verify whether the affected firmware version is deployed.
  • Restrict or remove network exposure of management interfaces and related services where possible.
  • Apply vendor-provided firmware updates or mitigations if available; if no fix is available, isolate or replace affected devices.
  • Review logs and access controls for unexpected requests related to qmiweb or CfgType=get_homeCfg.
  • Treat any data exposed through the affected request path as sensitive and rotate credentials or secrets if exposure is suspected.

Evidence notes

The supplied corpus includes the CVE record, NVD detail data, and a third-party technical advisory reference. NVD lists the vulnerability as modified on 2026-05-13, while the CVE itself was published on 2017-01-30; the modified date applies to the record, not the original vulnerability disclosure. No KEV listing is present in the supplied data.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-10181 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-10181

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-10181 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-10181

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.