Insufficient Authorization in Netlink ICT HG323RW Router
CVE-2026-96515
8.6HIGH
What is CVE-2026-96515?
The Netlink ICT HG323RW router is susceptible to a vulnerability stemming from lapses in authorization and input validation within its diagnostic script import feature. This flaw permits an authenticated attacker to upload and execute malicious scripts via the router's web management interface. Successful exploitation can lead to the execution of arbitrary operating system commands with root privileges, potentially resulting in full compromise of the device and posing significant risks to the surrounding network environment.
Affected Version(s)
Netlink ICT HG323RW Router Hardware Version (V3.7) and Affected Firmware (3.1.02-260228 Netlinkver)
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Muhammed Safvan.
