CVE-2026-11555
Analyzed Analyzed - Analysis Complete

Privilege Escalation in D-Link DGS-1100-08PD Web Interface

Vulnerability report for CVE-2026-11555, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-08

Last updated on: 2026-06-09

Assigner: VulDB

Description

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-08
Last Modified
2026-06-09
Generated
2026-06-29
AI Q&A
2026-06-08
EPSS Evaluated
2026-06-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dlink dgs-1100-08pd_firmware 1.00.006

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-272 The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the D-Link DGS-1100-08PD device, specifically in the processing of the file /etc/boa.conf within its Web Interface component.

The issue allows for a least privilege violation, meaning an attacker could gain higher privileges than intended.

The attack can be launched remotely but requires a high level of complexity and is considered difficult to exploit.

Despite the difficulty, an exploit is publicly available.

Impact Analysis

The vulnerability can lead to a least privilege violation, potentially allowing an attacker to perform actions or access resources beyond their authorized level.

Since the attack can be launched remotely, it increases the risk of unauthorized access to the device's web interface.

However, the exploitability is difficult and requires a high level of complexity, which may limit the likelihood of successful exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11555. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart