Junglewise Threat Intelligence

CVE-2026-86295: D-Link DIR-895L command injection in udhcpcd sendACK

CVE-2026-86295 · Severity: high · CVSS 8.3 · Published 2026-09-07

Technologies: D-Link DIR-895L. Vendors: D-Link.

Executive brief

D-Link DIR-895L is a wireless router used to provide internet connectivity and network services to homes and small businesses. A vulnerability in the DHCP server component allows an attacker to inject arbitrary system commands through a crafted Hostname parameter, potentially leading to remote code execution and full compromise of the router.

Technical details

A command injection vulnerability exists in the sendACK function of udhcpcd/serverpacket.c in D-Link DIR-895L firmware version A1_102b07. The vulnerable component is the DHCP server (udhcpcd), which processes client requests without properly sanitizing the Hostname argument. An attacker can send a specially crafted DHCP request containing shell metacharacters in the Hostname field to execute arbitrary commands on the router with system privileges. The attack requires network access to the router's DHCP service and can be performed remotely without authentication. A patch or firmware update may be available from D-Link.

Affected products

  • D-Link DIR-895L A1_102b07

Timeline

  • 2026-09-07: disclosed

References

Related threats