Impact
A weakness in the main function of the /HNAP1/dllog.cgi CGI binary on D-Link to send crafted requests that result in the disclosure of sensitive information. The flaw stems from improper access control, as indicated by the CWE-200 and CWE-284 enumerations, and allows data that should remain confidential to be exposed.
Affected Systems
All D-Link DIR-882 routers running firmware version 20260814 or earlier are affected. The vulnerability resides in the CGI binary included with the router’s web interface and impacts every unit variant using the listed firmware revision.
Risk and Exploitability
The CVSS score of 6.9 shows moderate risk, while the EPSS score of less than 1 % indicates a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, yet an exploit is publicly available and can be executed remotely, allowing an attacker to retrieve confidential data without privileged access or escalation.
OpenCVE Enrichment