← Browse

CVE-2026-90880

Medium

Elevated severity or exploit probability.

CVSS base
7.4 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
EPSS — probability of exploitation (30 days)
1.9%
79.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-74
Published 2026-09-15 · modified 2026-09-15

Description

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

References

Official: NVD · CVE.org