---
id: CVE-2026-96515
title: |-
  This
  vulnerability exists in the Netlink ICT HG323RW router due to insufficient
  authorization and input validation controls in the diagnostic script import
  functionality
summary: |-
  This
  vulnerability exists in the Netlink ICT HG323RW router due to insufficient
  authorization and input validation controls in the diagnostic script import
  functionality. An authenticated attacker could exploit this vulnerability by
  uplo…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-434
  - CWE-862
vendor: Netlink ICT Pvt Ltd
product: Netlink ICT HG323RW Router
affected:
  - >-
    netlink_ict_hg323rw_router Hardware Version (V3.7) and Affected Firmware
    (3.1.02-260228 Netlinkver)
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:17:59.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96515'
references:
  - url: >-
      https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2026-0473
    label: vdisclose@cert-in.org.in
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T14:40:29.568639Z'
cvssSource: cna
ingestedAt: '2026-09-24T12:42:45.223Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/whoami-012/CVE-2026-96515'
  checkedAt: '2026-09-25T08:21:26.199Z'
exploitAvailable: true
---

## Overview

This
vulnerability exists in the Netlink ICT HG323RW router due to insufficient
authorization and input validation controls in the diagnostic script import
functionality. An authenticated attacker could exploit this vulnerability by
uploading and executing a specially crafted script through the web management
interface.





Successful exploitation of this vulnerability
could allow the attacker to execute arbitrary operating system commands with
root privileges resulting in complete compromise of the affected device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
