Description
A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-06-08: | Advisory disclosed |
| 2026-06-08: | VulDB entry created |
| 2026-06-08: | VulDB entry last update |
Credits
yinfantasy (VulDB User)
References
vuldb.com/vuln/369165 (VDB-369165 | D-Link DGS-1100-08PD Web boa.conf least privilege violation)
vuldb.com/vuln/369165/cti (VDB-369165 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11555 (CVE-2026-11555 | CVE Analysis and Report)
vuldb.com/submit/834824 (Submit #834824 | D-link DGS-1100-08PD v1.00.006 Misconfiguration)
www.notion.so/...14e5cb80848bc4e3129dfafa29?source=copy_link
www.dlink.com/