D-Link DIR895LA1 Command Injection Vulnerability in DHCP Daemon
Vulnerability
A command injection vulnerability has been identified in the DHCP daemon service of the D-Link DIR895LA1 router, specifically in version 102b07. This vulnerability arises during the lease renewal process, where the DHCP hostname parameter is improperly sanitized before being appended to a system command. As a result, when a DHCP client sends a renewal request with a malicious hostname, it is possible to execute arbitrary commands with root privileges on the device.
Impact
Exploitation of this vulnerability allows for arbitrary command execution with root privileges on the affected device.
Added: Jan 9, 2026, 5:23 PM
Updated: Jan 9, 2026, 5:23 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
7.4remediation
0.0relevance
1.9threat
0.1urgency
2.9incentive
5.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
