CVE-2026-90880

medium

Description

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

References

https://www.dlink.com/

https://vuldb.com/vuln/403474/cti

https://vuldb.com/vuln/403474

https://vuldb.com/submit/928835

https://vuldb.com/cve/CVE-2026-90880

https://github.com/MeetFireAgain/cve/tree/main/dlink-dsl3782

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-78270

Details

Source: Mitre, NVD

Published: 2026-09-15

Updated: 2026-09-15

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Severity: High

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Severity: Medium

EPSS

EPSS: 0.01044