Command Injection Vulnerability in D-Link DSL-3782 Router
CVE-2026-90880
Key Information:
Badges
What is CVE-2026-90880?
A security flaw has been identified in the D-Link DSL-3782 router that permits remote command injection through the Diagnostics component. This vulnerability stems from improper handling of the Addr argument in the Diagnostics.asp script, allowing unauthorized execution of commands. Attackers can potentially exploit this flaw to gain control over the system. With an exploit already available publicly, it is crucial for users to apply security updates and ensure their networks are protected from potential attacks.
Affected Version(s)
DSL-3782 2016-07-28
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved