CVE-2026-15271
A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. The manipulation leads to least privilege violation. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitation is known to be difficult.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X
- EPSS probability
- 0.71%
- CWE
- CWE-272, CWE-266
- Published
- 2026-07-09
- Last modified
- 2026-07-10
Affected products
- TOTOLINK A3000RU
- TOTOLINK A3100R
- TOTOLINK A950RG
- TOTOLINK AC1200T10
- TOTOLINK CP450
- TOTOLINK CS185R_T10
- TOTOLINK EX200
Weakness type
Related vulnerabilities
- CVE-2026-79693 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79944 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2025-62299 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege...
- CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link...
- CVE-2026-15270 — D-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-11620 — TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation
- CVE-2026-11555 — D-Link DGS-1100-08PD Web boa.conf least privilege violation