CVE-2026-1505: D-Link DIR-615 URL Filter set_temp_nodes.php os command injection
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /settempnodes.php of the component URL Filter. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1505?
CVE-2026-1505 has a critical severity due to its potential for os command injection, allowing attackers to execute arbitrary commands on the affected system.
How do I fix CVE-2026-1505?
To mitigate CVE-2026-1505, update the D-Link DIR-615 firmware to the latest version provided by D-Link.
What systems are affected by CVE-2026-1505?
CVE-2026-1505 specifically affects the D-Link DIR-615 router version 4.10.
What is the attack vector for CVE-2026-1505?
CVE-2026-1505 can be exploited through the manipulation of the /set_temp_nodes.php file in the URL Filter component.
What does os command injection mean in the context of CVE-2026-1505?
In the context of CVE-2026-1505, os command injection refers to the ability of an attacker to execute arbitrary operating system commands on the vulnerable device.