Impact
The flaw exists in the UDP DHCP client daemon, specifically in the sendACK routine of serverpacket.c, where the Hostname argument is inadequately sanitized. An attacker can supply a crafted hostname string that gets executed as a command on the device, providing full code execution privileges. This can be used to install malware, modify configuration files, or create a backdoor, compromising both data confidentiality and system integrity.
Affected Systems
The vulnerability applies to D‑Link DIR‑895L routers running firmware version A1_102b07 or any earlier build that has not been upgraded to a security‑patched release. Devices with this firmware expose the vulnerable DHCP component via the TR‑069 Host Helper interface, allowing remote exploitation by anyone who can communicate DHCP messages to the device.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score of 2% indicates a low but non-zero exploitation probability, while the publicly available exploit demonstrates that the attack vector is remote and readily usable. The vulnerability is not listed in the CISA KEV catalog, but the presence of a demonstrated exploit suggests that attackers could target this device class at scale. The risk remains elevated because the vulnerability involves command injection, which typically allows bypassing normal access controls and executing arbitrary system commands.
OpenCVE Enrichment