🚨 CVE-2026-86295
A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
🎖@cveNotify

tzh00203 on Notion
D-Link DIR-895L Command Injection in udhcpd sendACK() TR-069 Host Helper | Notion
Vulnerability Title: Command Injection Vulnerability in udhcpd sendACK() TR-069 Host Helper of D-Link DIR-895L
September 7, 2026 17