Description
A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Update Firmware
AI Analysis

Impact

A weakness in the main function of the /HNAP1/dllog.cgi CGI binary on D-Link to send crafted requests that result in the disclosure of sensitive information. The flaw stems from improper access control, as indicated by the CWE-200 and CWE-284 enumerations, and allows data that should remain confidential to be exposed.

Affected Systems

All D-Link DIR-882 routers running firmware version 20260814 or earlier are affected. The vulnerability resides in the CGI binary included with the router’s web interface and impacts every unit variant using the listed firmware revision.

Risk and Exploitability

The CVSS score of 6.9 shows moderate risk, while the EPSS score of less than 1 % indicates a very low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, yet an exploit is publicly available and can be executed remotely, allowing an attacker to retrieve confidential data without privileged access or escalation.

Generated by OpenCVE AI on September 17, 2026 at 18:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the router to a newer firmware version from D-Link, which may address the vulnerability.
  • If immediate firmware upgrade is not possible, block or filter external access to the HNAP1 interface by configuring the router’s firewall or access control lists to allow only trusted internal IP ranges.
  • If the /HNAP1/dllog.cgi CGI function is not required for your network operation, disable it entirely or block its traffic and monitor logs for any unauthorized access attempts.

Generated by OpenCVE AI on September 17, 2026 at 18:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Title D-Link DIR-882 CGI Binary dllog.cgi main information disclosure
First Time appeared D-link
D-link dir-882
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:h:d-link:dir-882:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-882
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T13:54:48.205Z

Reserved: 2026-09-14T07:19:03.049Z

Link: CVE-2026-90881

cve-icon Vulnrichment

Updated: 2026-09-17T13:54:39.164Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T05:17:00.890

Modified: 2026-09-17T14:17:52.583

Link: CVE-2026-90881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control