Description
A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.
Published: 2026-07-09
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the Web Interface of D‑link DIR‑823G firmware 1.0.2B05_20181207 allows remote manipulation of the file /etc/boa/boa.conf. Exploiting this flaw leads to a least‑privilege violation, effectively turning a low‑privileged user into a privileged one and enabling unauthorized configuration changes. The flaw is classified under CWE‑266 and CWE‑272, indicating inadequate permission checks and weak default permissions.

Affected Systems

The vulnerability affects the D‑link DIR‑823G firmware 1.0.2B05_20181207. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 7.7 classifies this as High severity. Exploitation requires remote access, a high level of complexity, and is considered difficult, though publicly available exploits exist. The EPSS score of <1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation, but the potential impact warrants attention.

Generated by OpenCVE AI on July 29, 2026 at 11:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest official firmware update from D‑link to fix the available interface or restrict it to trusted internal networks only.
  • Set the file /etc/boa/boa.conf to strict permissions (e.g., mode 600, owned by root) to prevent unauthorized modifications.
  • Change default administrative credentials to a strong, unique password and rotate them regularly.
  • Consider placing the device behind a firewall and using a VPN for remote management if remote configuration is unavoidable.

Generated by OpenCVE AI on July 29, 2026 at 11:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.
Title D-link DIR-823G Web boa.conf least privilege violation
First Time appeared D-link
D-link dir-823g
Weaknesses CWE-266
CWE-272
CPEs cpe:2.3:h:d-link:dir-823g:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-823g
References
Metrics cvssV2_0

{'score': 7.1, 'vector': 'AV:N/AC:H/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-10T20:32:20.066Z

Reserved: 2026-07-09T14:48:56.967Z

Link: CVE-2026-15270

cve-icon Vulnrichment

Updated: 2026-07-10T19:09:56.707Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-272

    Least Privilege Violation