CVE-2026-2151: D-Link DIR-615 DMZ Host Feature adv_firewall.php os command injection
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file advfirewall.php of the component DMZ Host Feature. Such manipulation of the argument dmzipaddr leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2151?
CVE-2026-2151 has a medium severity level due to its potential for exploitation through OS command injection.
How do I fix CVE-2026-2151?
To fix CVE-2026-2151, update the D-Link DIR-615 firmware to the latest version provided by D-Link.
What impact can CVE-2026-2151 have on my network?
CVE-2026-2151 can allow an attacker to execute arbitrary operating system commands, potentially compromising your network security.
Which devices are affected by CVE-2026-2151?
CVE-2026-2151 specifically affects the D-Link DIR-615 routers running version 4.10.
How is CVE-2026-2151 exploited?
CVE-2026-2151 is exploited through manipulation of the 'dmz_ipaddr' argument in the adv_firewall.php file, leading to OS command injection.