CVE-2026-11497
גבוהה 8.8
תיאור (מקור, אנגלית)
A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
5.5 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-9/8/2026
- CWE
- CWE-266, CWE-272
מוצרים מושפעים
dlink: dcs-5615 firmware; dlink: dcs-5615
קישורים
- https://www.notion.so/D-link-DCS-5615_REV_1-01-00-3670ed14e5cb80e9be78f7d8dbf1… Vendor Advisory
- https://vuldb.com/cve/CVE-2026-11497 Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/834823 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/369117 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/369117/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product