CVE-2026-1506: D-Link DIR-615 MAC Filter Configuration adv_mac_filter.php os command injection
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /advmacfilter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1506?
CVE-2026-1506 is classified as a medium severity vulnerability due to its potential for unauthenticated command injection.
How do I fix CVE-2026-1506?
To fix CVE-2026-1506, update the D-Link DIR-615 to the latest firmware version released by D-Link.
What component is affected by CVE-2026-1506?
CVE-2026-1506 affects the MAC Filter Configuration feature in the D-Link DIR-615 router.
What type of vulnerability is CVE-2026-1506?
CVE-2026-1506 is an OS command injection vulnerability that can be exploited through improper validation of input in the adv_mac_filter.php file.
Can CVE-2026-1506 be exploited remotely?
Yes, CVE-2026-1506 can be exploited remotely without authentication, allowing attackers to execute commands on the affected device.