Description
This
vulnerability exists in the Netlink ICT HG323RW router due to insufficient
authorization and input validation controls in the diagnostic script import
functionality. An authenticated attacker could exploit this vulnerability by
uploading and executing a specially crafted script through the web management
interface.





Successful exploitation of this vulnerability
could allow the attacker to execute arbitrary operating system commands with
root privileges resulting in complete compromise of the affected device.
Published: 2026-09-24
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a command injection flaw in the diagnostic script import feature of the Netlink ICT HG323RW router. An attacker who can authenticate to the web management interface can upload a malicious script and have it executed with root privileges on the device. The result is full compromise of the router, allowing the attacker to modify configuration, intercept traffic, and pivot to other network assets.

Affected Systems

Affected devices are Netlink ICT Pvt Ltd Netlink ICT HG323RW routers, in particular firmware versions up to 3.1.02-260228. The vendor recommends upgrading to firmware 3.1.02-260904 (Internal Build Name: HG323RW_3.7 Netlinkver) to eliminate the flaw.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires authentication through the web interface, but once logged in, the attacker can upload and execute arbitrary OS commands as root. This makes the risk significant for any network hosting affected routers.

Generated by OpenCVE AI on September 24, 2026 at 13:23 UTC.

Remediation

Vendor Solution

Upgrade Netlink ICT HG323RW Router to latest firmware version 3.1.02-260904 (Internal Build Name: HG323RW_3.7 Netlinkver) https://netlinkict.com/firmwares/


OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update 3.1.02-260904 to the Netlink ICT HG323RW router
  • Restrict or disable the web‑based diagnostic script import function if it is not needed for operations
  • Limit web management access to trusted administrators and ensure strong authentication and network segmentation

Generated by OpenCVE AI on September 24, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uploading and executing a specially crafted script through the web management interface. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary operating system commands with root privileges resulting in complete compromise of the affected device.
Title Command Injection Vulnerability in Netlink ICT HG323RW Router
First Time appeared Netlink Ict Pvt Ltd
Netlink Ict Pvt Ltd netlink Ict Hg323rw Router
Weaknesses CWE-434
CWE-862
CPEs cpe:2.3:a:netlink_ict_pvt_ltd:netlink_ict_hg323rw_router:hardware_version_v3.7_and_affected_firmware_3.1.02-260228_netlinkver_:*:*:*:*:*:*:*
Vendors & Products Netlink Ict Pvt Ltd
Netlink Ict Pvt Ltd netlink Ict Hg323rw Router
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Netlink Ict Pvt Ltd Netlink Ict Hg323rw Router
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2026-09-24T14:41:10.388Z

Reserved: 2026-09-23T10:49:52.410Z

Link: CVE-2026-96515

cve-icon Vulnrichment

Updated: 2026-09-24T14:40:34.341Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T13:17:17.787

Modified: 2026-09-24T15:17:59.910

Link: CVE-2026-96515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T13:30:18Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type

  • CWE-862

    Missing Authorization