CVE-2026-2000 is a high-severity command injection vulnerability affecting DCN DCME-320 devices up to firmware version 20260121. An authenticated remote attacker can exploit a flaw in the apply_config function within the /function/system/basic/bridge_cfg.php component by manipulating the ip_list argument. This allows for arbitrary command execution with high impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks specific exploit intelligence or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20260121CPE matchmatch criteria | cpe:2.3:o:dcnetworks:dcme-320_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)
Mar 22, 2026DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)
Mar 22, 2026DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)
Mar 22, 2026DCN DCME-320 Command Injection (CVE-2024-51115; CVE-2026-2000)
Mar 22, 2026