CVE-2026-86295

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.

  • Published Sep 7, 2026
  • CVSS 5.5 medium
  • 2.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86295 at the National Vulnerability Database