CVE-2026-11497 PUBLISHED

D-Link DCS-5615 Boa Webserver boa.conf least privilege violation

Assigner: VulDB
Reserved: 07.06.2026 Published: 08.06.2026 Updated: 08.06.2026

A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of the file /etc/conf.d/boa/boa.conf of the component Boa Webserver. Such manipulation leads to least privilege violation. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor D-Link
Product DCS-5615
Versions
  • Version 1.01.00 is affected

Credits

  • yinfantasy (VulDB User) reporter

References

Problem Types

  • Least Privilege Violation CWE
  • Incorrect Privilege Assignment CWE