{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3hnetlinkhg323rw3.1.02-260228/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:netlink:hg323rw:3.1.02-260228:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-96515"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Netlink ICT HG323RW Router (firmware 3.1.02-260228)"],"_cs_severities":["high"],"_cs_tags":["cve","rce","network-device","router"],"_cs_type":"advisory","_cs_vendors":["Netlink"],"content_html":"\u003cp\u003eCVE-2026-96515 is a high-severity security vulnerability affecting Netlink ICT HG323RW routers, specifically firmware version 3.1.02-260228. The issue stems from the device's diagnostic import handler, hosted at the \u003ccode\u003e/boaform/formImportOMCIShell\u003c/code\u003e endpoint, which fails to correctly validate user-supplied files. An attacker with a low-privileged, authenticated web account on an adjacent network can upload a crafted shell script that is subsequently executed by the BOA process with root (UID 0) privileges. This vulnerability, identified as CWE-862 (Missing Authorization) and CWE-434 (Unrestricted Upload of File with Dangerous Type), was reported by Muhammed Safvan and acknowledged by CERT-In in advisory CIVN-2026-0473. With the recent publication of a functional proof-of-concept exploit, the risk of exploitation has increased significantly for unpatched devices. Defenders should ensure all affected hardware is updated to firmware version 3.1.02-260904, which removes the vulnerable endpoints.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a low-privileged web account on the Netlink ICT HG323RW router, potentially via factory default credentials or credential harvesting.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a connection to the router's web interface from an adjacent network segment.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the web portal and obtains necessary session/CSRF tokens to authorize subsequent API requests.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a multipart HTTP POST request containing a malicious shell script payload, targeting the \u003ccode\u003e/boaform/formImportOMCIShell\u003c/code\u003e endpoint and the \u003ccode\u003ebinary\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the multipart request to the target router, triggering the file upload mechanism.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ebin/boa\u003c/code\u003e process on the router saves the uploaded content to \u003ccode\u003e/tmp/omcishell\u003c/code\u003e without proper sanitization.\u003c/li\u003e\n\u003cli\u003eThe system's diagnostic handler invokes the execution sink, resulting in \u003ccode\u003e/bin/sh /tmp/omcishell\u003c/code\u003e being executed with UID 0.\u003c/li\u003e\n\u003cli\u003eAttacker gains a reverse shell or arbitrary command execution as the root user, facilitating full system control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to gain full control over the affected Netlink ICT HG323RW router with root-level privileges. This enables the attacker to intercept network traffic, modify device configurations, establish persistent backdoors, or use the device as a pivot point for further lateral movement within the private network. Given the device's role as a network gateway, this represents a significant compromise of the local infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Netlink ICT HG323RW routers to firmware version 3.1.02-260904 immediately, as this version disables the vulnerable \u003ccode\u003e/boaform/formImportOMCIShell\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict administrative web access to the router to trusted management VLANs or internal-only interfaces.\u003c/li\u003e\n\u003cli\u003eChange default factory credentials and enforce strong, unique passwords for all user accounts, including low-privileged ones.\u003c/li\u003e\n\u003cli\u003eMonitor internal network traffic for unexpected HTTP POST requests directed toward \u003ccode\u003e/boaform/formImportOMCIShell\u003c/code\u003e or \u003ccode\u003e/boaform/admin/formImportOMCIShell\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit for any unexplained processes spawned from \u003ccode\u003e/tmp/\u003c/code\u003e directory files, specifically those executing via \u003ccode\u003e/bin/sh\u003c/code\u003e or \u003ccode\u003e/bin/bash\u003c/code\u003e with UID 0.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T14:13:29Z","date_published":"2026-09-24T14:13:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96515/","summary":"A vulnerability in the Netlink ICT HG323RW router allows authenticated low-privileged users to achieve remote code execution as root via an insecure diagnostic import endpoint.","title":"Remote Code Execution in Netlink ICT HG323RW Routers via CVE-2026-96515","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96515/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:h:netlink:hg323rw:3.1.02-260228:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}