Sceawere

Vulnerability Detail

CVE-2026-90881UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link DIR-882 Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
D-Link
Product
DIR-882
Attack Type
Information Disclosure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-15T05:17:00.890Z",
  "pubdate": "2026-09-15T05:17:00.890Z",
  "executiveSummary": "A critical information disclosure vulnerability has been identified in the D-Link DIR-882 router, affecting all firmware versions up to 20260814.\nThe flaw resides within the /HNAP1/dllog.cgi CGI binary, specifically impacting the main function. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized access to sensitive system information.\nThe vulnerability allows for remote exploitation without requiring local network access or prior authentication, significantly increasing the risk profile for exposed devices.\nThe public availability of exploit code increases the likelihood of opportunistic attacks targeting this device. Successful exploitation leads to the leakage of system data, which could facilitate further unauthorized activities or provide reconnaissance data for secondary attacks.\nOrganizations and users relying on the D-Link DIR-882 must treat this vulnerability as high-risk, given the potential for remote, unauthenticated data exfiltration.",
  "technicalDetails": "The vulnerability is located in the CGI binary component /HNAP1/dllog.cgi, specifically within its main function. The root cause pertains to improper validation or handling of HTTP requests targeting this CGI endpoint, which allows the binary to leak sensitive internal information stored within the device's memory or configuration files to the requester.\nThe attack flow initiates with a remote attacker sending a specially crafted HTTP request to the /HNAP1/dllog.cgi endpoint. Because this endpoint does not correctly enforce authentication or input validation, it processes the malicious request and returns a response containing data that should remain restricted.\nThe exploitation method leverages the existing logic within the main function of the dllog.cgi binary. Upon receiving the manipulated request, the function fails to sanitize the input parameters or restrict the scope of the output, resulting in a state where internal process data or logging information is written directly to the HTTP response body.\nThe technical impact is characterized as an information disclosure vulnerability. By observing the responses from the vulnerable binary, an attacker can extract system logs, memory addresses, or internal network identifiers that were intended to be protected.\nThe vulnerability is remotely exploitable, requiring no interaction from a legitimate user and no valid administrative session. The affected versions include all firmware iterations up to 20260814, indicating a long-standing weakness in the handling of the HNAP (Home Network Administration Protocol) interface on this specific model.\nPost-exploitation, the information obtained can be leveraged to map the internal network structure, identify secondary vulnerabilities, or gather credentials if such data happens to be included in the leaked log contents. Since the exploit is already publicly available, the barrier to entry for an attacker is minimal, allowing for automated scanning and mass exploitation of internet-facing D-Link DIR-882 routers."
}
CVE-2026-90881: D-Link DIR-882 Information Disclosure (MEDIUM Severity, CVSS: 5.3) | Sceawere