{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dir-895l-a1_102b07/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:dlink:dir-895l_firmware:a1_102b07:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-86295"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DIR-895L (A1_102b07)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eA remote command injection vulnerability (CVE-2026-86295) has been identified in D-Link DIR-895L routers running firmware version A1_102b07. The flaw resides within the \u003ccode\u003esendACK\u003c/code\u003e function in the \u003ccode\u003eudhcpcd/serverpacket.c\u003c/code\u003e file of the \u003ccode\u003eudhcpcd\u003c/code\u003e component. An unauthenticated attacker can trigger this vulnerability by sending a specially crafted DHCP request containing a malicious payload within the Hostname argument. This allows for arbitrary command execution on the target device with the privileges of the affected process. Given that the exploit code has been made publicly available, there is a significant risk of exploitation by threat actors targeting residential and small office/home office (SOHO) network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote control over the affected D-Link DIR-895L router. Attackers could leverage this access to intercept network traffic, redirect DNS queries, pivot into the local network, or incorporate the device into a botnet. This represents a critical risk to data confidentiality and integrity for any users on the local network managed by the vulnerable router.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all D-Link DIR-895L devices within the network environment.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative interfaces and DHCP-related management ports to trusted IP ranges where possible.\u003c/li\u003e\n\u003cli\u003eMonitor for firmware updates from the vendor and apply patches immediately upon availability.\u003c/li\u003e\n\u003cli\u003eIsolate affected hardware from critical segments until a vendor-supplied update is verified and installed.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T12:52:59Z","date_published":"2026-09-07T12:52:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/","summary":"An unauthenticated remote command injection vulnerability in the D-Link DIR-895L router allows attackers to execute arbitrary code via a malicious Hostname argument in the udhcpcd component.","title":"Remote Command Injection in D-Link DIR-895L","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - DIR-895L (A1_102b07)","version":"https://jsonfeed.org/version/1.1"}