CVE-2026-15270: D-link DIR-823G Web boa.conf least privilege violation
A weakness has been identified in D-link DIR-823G 1.0.2B0520181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15270?
CVE-2026-15270 has a high severity rating of 7.5.
What impact does CVE-2026-15270 have?
CVE-2026-15270 allows for a least privilege violation, potentially leading to unauthorized access.
How do I fix CVE-2026-15270?
To mitigate CVE-2026-15270, update the D-Link DIR-823G firmware to the latest version provided by D-Link.
Is CVE-2026-15270 exploitable remotely?
Yes, CVE-2026-15270 can be exploited remotely.
Which D-Link model is affected by CVE-2026-15270?
CVE-2026-15270 affects the D-Link DIR-823G model.