CVE-2026-2000: DCN DCME-320 Web Management Backend bridge_cfg.php apply_config command injection
A vulnerability was found in DCN DCME-320 up to 20260121. Impacted is the function applyconfig of the file /function/system/basic/bridgecfg.php of the component Web Management Backend. Performing a manipulation of the argument iplist results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2000?
CVE-2026-2000 has been classified as a high severity vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-2000?
To fix CVE-2026-2000, update the DCN DCME-320 software to a version newer than 20260121.
What components are impacted by CVE-2026-2000?
CVE-2026-2000 specifically affects the apply_config function within the bridge_cfg.php file of the Web Management Backend.
Can CVE-2026-2000 be exploited remotely?
Yes, CVE-2026-2000 can be exploited remotely, enabling an attacker to execute unauthorized commands.
Which versions of DCN DCME-320 are vulnerable to CVE-2026-2000?
DCN DCME-320 versions up to and including 20260121 are vulnerable to CVE-2026-2000.