CVE-2026-90881: D-Link DIR-882 CGI Binary dllog.cgi main information disclosure
A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
D-Link DIR-882 devices are affected through the /HNAP1/dllog.cgi endpoint in the CGI Binary component. The issue can be attacked remotely and requires no privileges or user interaction according to the supplied vector.
Is public exploit code available?
Yes. The exploit has been publicly disclosed and could be used in attacks.
What is the known impact of successful exploitation?
Successful manipulation of the affected main function can disclose information. The provided assessment indicates confidentiality impact is low, with no stated integrity or availability impact.