Junglewise Threat Intelligence

CVE-2026-90881: D-Link DIR-882 information disclosure in CGI binary

CVE-2026-90881 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Vendors: D-Link.

Executive brief

D-Link DIR-882 is a wireless router used in home and office networks. A vulnerability in the router's web management interface (specifically the /HNAP1/dllog.cgi file) allows an attacker to remotely extract sensitive information from the device without requiring authentication. An attacker could potentially gain access to configuration data, logs, or other confidential information stored on the router.

Technical details

The vulnerability exists in the main function of the CGI binary at /HNAP1/dllog.cgi in D-Link DIR-882 firmware up to version 20260814. The affected component fails to properly validate or restrict access to sensitive data exposed through the web interface. The vulnerability is remotely exploitable over the network without authentication or user interaction required. An attacker can send a crafted request to the dllog.cgi endpoint to manipulate the application logic and retrieve sensitive information such as logs, configuration, or other protected data. Public exploit code is available, increasing the likelihood of active exploitation.

Affected products

  • D-Link DIR-882 up to 20260814

Timeline

  • 2026-09-15: disclosed
  • other: Public exploit code available

References