Tag
high
advisory
CVE-2026-16445: Dracut Command Injection via Malicious DHCP Options
1 TTP 1 CVEA command injection vulnerability exists in dracut's NetworkManager-based initrd network module that allows a remote attacker on an adjacent network to achieve root code execution within the initramfs during system boot by providing specially crafted DHCP options without proper escaping.
dracut
command-injection
initramfs
dhcp
linux
cve
1t
1c
high
advisory
D-Link DIR-822 A_101 Command Injection via DHCP Hostname
2 rules 1 TTP 1 CVEA command injection vulnerability exists in D-Link DIR-822 A_101, specifically within the udhcpd DHCP service; by manipulating the Hostname argument, a remote attacker can inject commands, but the affected product is no longer supported.
DIR-822 A_101
command-injection
dhcp
iot
2r
1t
1c