CVE-2026-86295

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 11:17

Updated : 2026-09-08 16:18


NVD link : CVE-2026-86295

Mitre link : CVE-2026-86295

CVE.ORG link : CVE-2026-86295


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')