Web Interface Vulnerability in D-Link DGS-1100-08PD Products
CVE-2026-11555
Key Information:
- Vendor
D-link
- Status
- Vendor
- CVE Published:
- 8 June 2026
Badges
What is CVE-2026-11555?
A vulnerability in the Web Interface of the D-Link DGS-1100-08PD switch allows for unauthorized manipulation of the /etc/boa.conf file. This manipulation can lead to a violation of least privilege principles, potentially allowing an attacker to execute unauthorized actions. The attack can be initiated remotely, necessitating considerable skill and complexity to exploit. Publicly available exploit code indicates an ongoing risk for users of this device.
Affected Version(s)
DGS-1100-08PD 1.00.006
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved