D-Link DIR-842 Vulnerability in vsftpd Configuration Settings
CVE-2026-19893

2.3LOW

Key Information:

Vendor

D-link

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-19893?

A misconfiguration vulnerability has been identified in the D-Link DIR-842 router version 2.01.B04, specifically within the vsftpd configuration file (/etc/vsftpd.conf). This weakness allows for incorrect default permissions, which could be exploited remotely. While the complexity of the attack is categorized as high, it opens a pathway for potential unauthorized access, significantly impacting the security posture of systems utilizing this configuration.

Affected Version(s)

DIR-842 2.01.B04

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

L14Utopia (VulDB User)
.