Description
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05. The affected element is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Performing a manipulation results in least privilege violation. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-06-07: | Advisory disclosed |
| 2026-06-07: | VulDB entry created |
| 2026-06-07: | VulDB entry last update |
Credits
L-14 (VulDB User)
References
vuldb.com/vuln/369112 (VDB-369112 | D-Link DIR-823G vsftpd vsftpd.conf least privilege violation)
vuldb.com/vuln/369112/cti (VDB-369112 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11492 (CVE-2026-11492 | CVE Analysis and Report)
vuldb.com/submit/834816 (Submit #834816 | D-Link DIR823G V1.0.2B05_20181207 Misconfiguration)
www.notion.so/...ba989080ac97fdc36d2fb5e57d?source=copy_link
www.dlink.com/