CVE-2026-1506
Last modified
CVE-2026-1506 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. EPSS estimates a 5.07% chance of exploitation in the next 30 days.
Description
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php of the component MAC Filter Configuration. This manipulation of the argument mac causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dir-615 Firmware | 4.10 |
References
- https://pentagonal-time-3a7.notion.site/DIR-615-MAC_FILTER-2e7e5dd4c5a58091b027f50271cc7c6aExploit, Third Party Advisory
- https://vuldb.com/?ctiid.343118Permissions Required, VDB Entry
- https://vuldb.com/?id.343118Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.737078Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-1506?
How severe is CVE-2026-1506?
How do I fix CVE-2026-1506?
Are you affected by CVE-2026-1506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
