Junglewise Threat Intelligence

CVE-2026-11555: D-Link DGS-1100-08PD privilege violation in web interface

CVE-2026-11555 · Severity: low · CVSS 3.7 · Published 2026-06-08

Vendors: D-Link.

Executive brief

A security vulnerability exists in the web management interface of the D-Link DGS-1100-08PD network switch. An attacker could potentially manipulate system configuration files to gain unauthorized privileges or bypass intended security restrictions. While the attack can be performed over the network, it is considered difficult to execute due to the high level of complexity required.

Technical details

A vulnerability classified as Incorrect Privilege Assignment (CWE-266) and Least Privilege Violation (CWE-272) exists in D-Link DGS-1100-08PD firmware version 1.00.006. The issue resides in the web interface component during the processing of the /etc/boa.conf configuration file. A remote attacker can exploit this to violate least privilege principles, though the attack requires high complexity (AC:H). Successful exploitation allows for unauthorized manipulation of system settings, though it does not directly result in data confidentiality or availability loss according to reported metrics. Public exploit code is reportedly available.

Affected products

  • D-Link DGS-1100-08PD 1.00.006

Timeline

  • 2026-06-08: disclosed: Initial publication date

References