<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:dlink:dir-895l_firmware:a1_102b07:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3odlinkdir-895l_firmwarea1_102b07/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 12:52:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3odlinkdir-895l_firmwarea1_102b07/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Command Injection in D-Link DIR-895L</title><link>https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/</link><pubDate>Mon, 07 Sep 2026 12:52:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/</guid><description>An unauthenticated remote command injection vulnerability in the D-Link DIR-895L router allows attackers to execute arbitrary code via a malicious Hostname argument in the udhcpcd component.</description><content:encoded><![CDATA[<p>A remote command injection vulnerability (CVE-2026-86295) has been identified in D-Link DIR-895L routers running firmware version A1_102b07. The flaw resides within the <code>sendACK</code> function in the <code>udhcpcd/serverpacket.c</code> file of the <code>udhcpcd</code> component. An unauthenticated attacker can trigger this vulnerability by sending a specially crafted DHCP request containing a malicious payload within the Hostname argument. This allows for arbitrary command execution on the target device with the privileges of the affected process. Given that the exploit code has been made publicly available, there is a significant risk of exploitation by threat actors targeting residential and small office/home office (SOHO) network infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full remote control over the affected D-Link DIR-895L router. Attackers could leverage this access to intercept network traffic, redirect DNS queries, pivot into the local network, or incorporate the device into a botnet. This represents a critical risk to data confidentiality and integrity for any users on the local network managed by the vulnerable router.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Inventory all D-Link DIR-895L devices within the network environment.</li>
<li>Restrict access to administrative interfaces and DHCP-related management ports to trusted IP ranges where possible.</li>
<li>Monitor for firmware updates from the vendor and apply patches immediately upon availability.</li>
<li>Isolate affected hardware from critical segments until a vendor-supplied update is verified and installed.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>