CVE-2026-2000 | DCN DCME-320 up to 20260121 Web Management Backend bridge_cfg.php apply_config ip_list command injection
A vulnerability was found in DCN DCME-320 up to 20260121. It has been rated as critical. Impacted is the function apply_config of the file /function/system/basic/bridge_cfg.php of the component Web Management Backend. Performing a manipulation of the argument ip_list results in command injection.
This vulnerability is reported as CVE-2026-2000. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.