CVE-2026-90881
Deferred Deferred - Pending Action

Information Disclosure in D-Link DIR-882 Router

Vulnerability report for CVE-2026-90881, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulDB

Description

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-16
AI Q&A
2026-09-15
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
d-link dir-882 to 20260814 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-90881 is an information disclosure vulnerability in D-Link DIR-882 routers up to firmware version 20260814. It affects the CGI binary in the file /HNAP1/dllog.cgi of the component CGI Binary. The flaw allows unauthenticated attackers to remotely access sensitive system information such as logs, memory usage, running processes, and network details by exploiting a lack of authentication checks in the web server.

Detection Guidance

To detect this vulnerability, check if your D-Link DIR-882 router responds to unauthenticated HTTP GET requests to /HNAP1/dllog.cgi or /HNAP1/dlquickvpnsettings.cgi. Use curl commands like 'curl http://<router-ip>/HNAP1/dllog.cgi' or 'curl http://<router-ip>/HNAP1/dlquickvpnsettings.cgi' to see if sensitive data is returned without authentication.

Impact Analysis

This vulnerability allows attackers to remotely gather sensitive device and network information without authentication. Exploiting it could expose system logs, running services, network interfaces, memory usage, and VPN configurations. Attackers could use this data to identify additional vulnerabilities or services for further attacks on your network.

Compliance Impact

This vulnerability allows unauthenticated remote access to sensitive system information including logs, memory usage, running processes, network interfaces, and VPN configurations. Such unauthorized data exposure could violate compliance requirements under GDPR (data protection) and HIPAA (privacy and security) by enabling unauthorized access to personal or sensitive information.

Mitigation Strategies

Immediately update the router firmware to the latest version. If no update is available, disable remote access to the router's web interface and block external HTTP requests to the vulnerable endpoints at the network perimeter. Consider replacing the device if the vendor does not provide a patch.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90881. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart