← Vulnerability feed

Vulnerability record · CVE-2026-1448 · published 27 January 2026

CVE-2026-1448: Dlink dir-615 firmware command injection vulnerability

Dlink · Dir 615 Firmware

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

7.3 CVSS 4.0 High EPSS 5.8% · top 7.2% CWE-77 · Command injectionCWE-78 · OS command injection
7.3CVSS 4.0 base score, v2 8.3
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://pentagonal-time-3a7.notion.site/DIR-615-v4-10-2e7e5dd4c5a580a5aac5c8ce35933396?pvs=73 ExploitThird Party Advisory
https://vuldb.com/?ctiid.342880 Permissions RequiredVDB Entry
https://vuldb.com/?id.342880 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.737006 Third Party AdvisoryVDB Entry
https://www.dlink.com/ Product

Track CVE-2026-1448 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16920D-Link router PingTest CGI command injection allows unauthenticated RCEMultiple D-Link router and powerline models expose a PingTest common gateway interface that passes arbitrary input into a system command without sani…KEVEPSS 100%analysed9.8CVE-2014-8361Realtek SDK miniigd SOAP service remote code executionThe miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw…KEVEPSS 100%analysed10.0CVE-2018-25115Dlink dir-110 firmware os command injection vulnerabilityMultiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vuln…EPSS 10%9.8CVE-2021-42627D-Link DIR-615 WAN page exposed without authenticationThe WAN configuration page wan.htm on D-Link DIR-615 devices running firmware 20.06 is reachable directly without authentication. An unauthenticated …EPSS 63%analysed9.8CVE-2021-37388Dlink dir-615 firmware classic buffer overflow vulnerabilityA buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver …EPSS 3.7%9.8CVE-2018-15839D-Link DIR-615 router buffer overflow via long Authorization headerD-Link DIR-615 firmware contains a memory buffer overflow (CWE-119) triggered by an overly long Authorization HTTP header. The flaw is remotely reach…EPSS 45%analysed8.8CVE-2019-17525Dlink dir-615 firmware improper restriction of authentication attempts vulnerabilityThe login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.EPSS 5.8%8.7CVE-2013-10050Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authentica…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2026-1448), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.