CVE-2026-90881

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

  • Published Sep 15, 2026
  • CVSS 5.5 medium
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90881 at the National Vulnerability Database