CVE-2026-86295CWE-74CWE-77

D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection

High · published September 7, 2026

CVSS v3.1
8.3
EPSS
In the wild
Unconfirmed
What it is

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.

The record
Technical detail
CVSS v3.1
8.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P
EPSS
Not scored
Weaknesses
CWE-74 · Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'); CWE-77 · Improper Neutralization of Special Elements used in a Command ('Command Injection')
Published
2026-09-07T10:15Z
Timeline
  • 07 SEP 10:15Z
    D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
    cvelistv5