Answer in brief
CVE-2026-96515 records a High severity (CVSS 8.6) vulnerability in Command Injection Vulnerability in Netlink ICT HG323RW Router. The current sources do not mark it as known exploited. The current feed maps Netlink ICT Pvt Ltd/Netlink ICT HG323RW Router (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Netlink ICT Pvt Ltd/Netlink ICT HG323RW Router (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Netlink ICT Pvt Ltd/Netlink ICT HG323RW Routergeneric | Hardware Version (V3.7) and Affected Firmware (3.1.02-260228 Netlinkver) | Not reported |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 24, 2026
This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uploading and executing a specially crafted script through the web management interface. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary operating system commands with root privileges resulting in complete compromise of the affected device.
Quoted source text, attributed separately from HOL analysis.