vulnerability exists in the Netlink ICT HG323RW router due to insufficient
authorization and input validation controls in the diagnostic script import
functionality. An authenticated attacker could exploit this vulnerability by
uploading and executing a specially crafted script through the web management
interface.
Successful exploitation of this vulnerability
could allow the attacker to execute arbitrary operating system commands with
root privileges resulting in complete compromise of the affected device.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Netlink ICT HG323RW Router to latest firmware version 3.1.02-260904 (Internal Build Name: HG323RW_3.7 Netlinkver) https://netlinkict.com/firmwares/
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uploading and executing a specially crafted script through the web management interface. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary operating system commands with root privileges resulting in complete compromise of the affected device. | |
| Title | Command Injection Vulnerability in Netlink ICT HG323RW Router | |
| First Time appeared |
Netlink Ict Pvt Ltd
Netlink Ict Pvt Ltd netlink Ict Hg323rw Router |
|
| Weaknesses | CWE-434 CWE-862 |
|
| CPEs | cpe:2.3:a:netlink_ict_pvt_ltd:netlink_ict_hg323rw_router:hardware_version_v3.7_and_affected_firmware_3.1.02-260228_netlinkver_:*:*:*:*:*:*:* | |
| Vendors & Products |
Netlink Ict Pvt Ltd
Netlink Ict Pvt Ltd netlink Ict Hg323rw Router |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2026-09-24T11:59:40.882Z
Reserved: 2026-09-23T10:49:52.410Z
Link: CVE-2026-96515
No data.
Status : Received
Published: 2026-09-24T13:17:17.787
Modified: 2026-09-24T13:17:17.787
Link: CVE-2026-96515
No data.
OpenCVE Enrichment
Updated: 2026-09-24T13:30:18Z