Threat Intelligence / CVE / CVE-2026-2142

CVE-2026-2142

CVSS 7.2 (HIGH) · EPSS 0.1% · Priority 4.8/10 · Published 2026-02-08

As of 2026-02-10, CVE-2026-2142 is a CVSS 7.2 (HIGH-severity) vulnerability. EPSS exploitation probability 0.1%. Threadlinqs Intelligence tracks 1 threat exploiting it.

Last updated: 2026-02-10

A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file /goform/set_qos. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-77, CWE-78

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2026-2142 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.