GHSA-8qr5-3j7x-xm4jMediumCVSS 8.3
A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86295
- https://tzh00203.notion.site/D-Link-DIR-895L-Command-Injection-in-udhcpd-sendACK-TR-069-Host-Helper-33cb5c52018a80aaaa5be16a761ff457
- https://vuldb.com/cve/CVE-2026-86295
- https://vuldb.com/submit/906296
- https://vuldb.com/vuln/399457
- https://vuldb.com/vuln/399457/cti
- https://www.dlink.com
- https://github.com/advisories/GHSA-8qr5-3j7x-xm4j