Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2000

33
FAUCET Score

CVE-2026-2000 is a high-severity command injection vulnerability affecting DCN DCME-320 devices up to firmware version 20260121. An authenticated remote attacker can exploit a flaw in the apply_config function within the /function/system/basic/bridge_cfg.php component by manipulating the ip_list argument. This allows for arbitrary command execution with high impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks specific exploit intelligence or community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
<= 20260121CPE matchmatch criteria
cpe:2.3:o:dcnetworks:dcme-320_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
17.15%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1715 is in the 95th percentile among its peer group of 5,530 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

3cxvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted

Vendor Advisories (4)

horillallm-horilla-d5964835ef770421HIGH

DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)

Mar 22, 2026
inveniosoftwarellm-inveniosoftware-1617ed08ccbd8aa7HIGH

DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)

Mar 22, 2026
jitsillm-jitsi-93e3a47ffd314585HIGH

DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)

Mar 22, 2026
3cxllm-3cx-687b723e696eaf68HIGH

DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)

Mar 22, 2026

References

github.com / physicszq/Routers/tree/main/Dcme
ExploitThird Party Advisory
vuldb.com
Permissions RequiredVDB Entry
vuldb.com
Third Party AdvisoryVDB Entry
vuldb.com
Third Party AdvisoryVDB Entry