CVE-2026-96515
8.6Netlink · ICT HG323RW Router
A vulnerability in the Netlink ICT HG323RW router allows authenticated attackers to execute arbitrary system commands with root privileges via the diagnostic script import function.
Executive summary
An authenticated command injection vulnerability in the Netlink ICT HG323RW router firmware enables attackers to gain full root-level control of the device.
Vulnerability
The flaw stems from missing authorization and unrestricted file upload controls (CWE-862 and CWE-434) within the diagnostic script import feature. An authenticated attacker with low privileges can upload and execute malicious scripts through the web management interface to achieve root-level code execution.
Business impact
Successful exploitation results in a complete compromise of the router, providing an attacker with persistent, high-privileged access to the network perimeter. This level of access enables data interception, lateral movement into internal systems, and potential total loss of confidentiality, integrity, and availability for the affected network segment. With a CVSS score of 8.6, this represents a high-severity risk that requires immediate attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Update the affected Netlink ICT HG323RW router firmware to the patched version 3.1.02-260904 (Internal Build Name: HG323RW_3.7 Netlinkver) available via the vendor support portal.
Proactive Monitoring: Review web management interface access logs for unauthorized attempts to access diagnostic pages or anomalous file upload activity.
Compensating Controls: Restrict access to the router management interface to trusted administrative IP addresses only, and disable the diagnostic script import feature if it is not required for standard operations.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete device takeover, organizations utilizing the Netlink ICT HG323RW router must prioritize this firmware update. Administrators should verify the current firmware version across all deployed units and apply the patch immediately to eliminate the risk of remote command execution.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by This vulnerability is reported by Muhammed Safvan., per the CVE Program record.