CVE-2026-96515 is an authenticated OS command-injection vulnerability in the Netlink ICT HG323RW router's diagnostic script-import functionality. Insufficient authorization and input-validation controls allow an authenticated user of the web-management interface to upload and execute a specially crafted diagnostic script, resulting in execution of arbitrary operating-system commands with root privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 22-file repository documents and implements CVE-2026-96515, an authenticated authorization-bypass and dangerous-file-upload vulnerability in Netlink ICT HG323RW V3.7 firmware 3.1.02-260228 Netlinkver. Its sole executable component, poc/poc.py, is a Python 3 PoC that logs into the router over HTTP, extracts login verification and CSRF values, obtains an authenticated CSRF token, starts a local TCP listener, and uploads a FIFO-based /bin/sh reverse-shell script to /boaform/formImportOMCIShell. Static firmware evidence indicates BOA stores the upload at /tmp/omcishell and runs /bin/sh /tmp/omcishell as UID 0, producing root-level interactive command execution when the callback succeeds. The script includes safety restrictions to non-public IPv4 targets/callbacks, password prompting, sanitised debug output, and explicit execution confirmation. The repository is not tied to Metasploit, Nuclei, or another exploit framework. Supporting Markdown and text evidence documents BOA binary strings, authentication configuration, factory-reset account provisioning, firmware integrity hashes, and owner-supplied runtime observations. It also includes vulnerable and CNA-listed patched firmware archives, though they are not source code. Evidence supports only the assessed vulnerable release; the listed fix is 3.1.02-260904, where both /boaform/formImportOMCIShell and /boaform/admin/formImportOMCIShell reportedly return HTTP 404. This is not pre-authentication RCE: a valid limited-role session, verification value, and CSRF token are required.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated remote command-execution vulnerability in the Netlink ICT HG323RW router's diagnostic-script import function. Crafted script uploads via the web management interface can execute OS commands as root, resulting in complete device compromise.
A high-severity command-injection vulnerability in the Netlink ICT HG323RW router's diagnostic script-import function. An authenticated attacker can upload a crafted script through the web management interface and execute arbitrary operating-system commands with root privileges, fully compromising the device.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.