Junglewise Threat Intelligence

CVE-2026-15270: D-Link DIR-823G privilege escalation in web interface

CVE-2026-15270 · Severity: high · CVSS 7.5 · Published 2026-07-09

Technologies: D-Link DIR-823G. Vendors: D-Link.

Executive brief

A security vulnerability exists in the D-Link DIR-823G router's web management interface. An attacker with low-level access could manipulate configuration files to gain higher privileges than intended. This could allow an unauthorized user to take control of the device, potentially leading to data interception or network disruption.

Technical details

A least privilege violation (CWE-272) and incorrect privilege assignment (CWE-266) vulnerability exists in the D-Link DIR-823G router running firmware version 1.0.2B05_20181207. The flaw is located within the web interface component, specifically involving the handling of the /etc/boa/boa.conf configuration file. A remote attacker with low-privileged credentials can exploit this vulnerability through complex manipulation to escalate their privileges. Successful exploitation allows the attacker to bypass intended security restrictions and perform actions with elevated authority. Public exploit code is reportedly available.

Affected products

  • D-Link DIR-823G 1.0.2B05_20181207

Timeline

  • 2026-07-09: advisory: Vulnerability published by NVD/VulDB

References

Related threats