CVE-2026-11492

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
References
Link Resource
https://vuldb.com/cve/CVE-2026-11492 Third Party Advisory VDB Entry
https://vuldb.com/submit/834816 Third Party Advisory VDB Entry
https://vuldb.com/vuln/369112 Third Party Advisory VDB Entry
https://vuldb.com/vuln/369112/cti Permissions Required VDB Entry
https://www.dlink.com/ Product
https://www.notion.so/D-Link-DIR823G-V1-0-2B05_20181207-3671f5ba989080ac97fdc36d2fb5e57d?source=copy_link Exploit Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-823g_firmware:1.0.2b05:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-823g:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-08 07:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-11492

Mitre link : CVE-2026-11492

CVE.ORG link : CVE-2026-11492


JSON object : View

Products Affected

dlink

  • dir-823g
  • dir-823g_firmware
CWE
CWE-266

Incorrect Privilege Assignment

CWE-272

Least Privilege Violation