CVE-2026-11555
Received Received - Intake
Privilege Escalation in D-Link DGS-1100-08PD Web Interface

Publication date: 2026-06-08

Last updated on: 2026-06-08

Assigner: VulDB

Description
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-08
Last Modified
2026-06-08
Generated
2026-06-09
AI Q&A
2026-06-08
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
d-link dgs-1100-08pd 1.00.006
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-272 The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the D-Link DGS-1100-08PD device, specifically in the processing of the file /etc/boa.conf within its Web Interface component.

The issue allows for a least privilege violation, meaning an attacker could gain higher privileges than intended.

The attack can be launched remotely but requires a high level of complexity and is considered difficult to exploit.

Despite the difficulty, an exploit is publicly available.

Impact Analysis

The vulnerability can lead to a least privilege violation, potentially allowing an attacker to perform actions or access resources beyond their authorized level.

Since the attack can be launched remotely, it increases the risk of unauthorized access to the device's web interface.

However, the exploitability is difficult and requires a high level of complexity, which may limit the likelihood of successful exploitation.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11555. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart