CVE-2026-2151

HIGH

D-Link DIR-615 4.10 - OS Command Injection via DMZ Host Feature dmz_ipaddr Argument

Title source: llm
STIX 2.1

Description

A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the component DMZ Host Feature. Such manipulation of the argument dmz_ipaddr  leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.344853
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.344853
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.748031
Product product
https://www.dlink.com/

Scores

CVSS v3 7.2
EPSS 0.0068
EPSS Percentile 71.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
dlink/dir-615_firmware 4.10
Published Feb 08, 2026
Tracked Since Feb 18, 2026