CVE-2026-96515: Command Injection Vulnerability in Netlink ICT HG323RW Router
This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uploading and executing a specially crafted script through the web management interface.
Successful exploitation of this vulnerability could allow the attacker to execute arbitrary operating system commands with root privileges resulting in complete compromise of the affected device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netlink ICT HG323RW Routerto a version that resolves this vulnerability.Fixed in 3.1.02-260904
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be authenticated to the router's web management interface and able to use the diagnostic script import functionality.
What is the likely impact if exploitation succeeds?
A crafted uploaded script can be executed to run arbitrary operating-system commands with root privileges, resulting in complete compromise of the affected device.