Insufficient Authorization in Netlink ICT HG323RW Router
CVE-2026-96515

8.6HIGH

Key Information:

Vendor
CVE Published:
24 September 2026

What is CVE-2026-96515?

The Netlink ICT HG323RW router is susceptible to a vulnerability stemming from lapses in authorization and input validation within its diagnostic script import feature. This flaw permits an authenticated attacker to upload and execute malicious scripts via the router's web management interface. Successful exploitation can lead to the execution of arbitrary operating system commands with root privileges, potentially resulting in full compromise of the device and posing significant risks to the surrounding network environment.

Affected Version(s)

Netlink ICT HG323RW Router Hardware Version (V3.7) and Affected Firmware (3.1.02-260228 Netlinkver)

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Muhammed Safvan.
.