AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-9031

MEDIUM · CVSS 6.8 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

An input validation vulnerability in the HTTP-WRITEOEM handler allows for insufficiently validated user-supplied data to disrupt internal flash-write operations. Exploitation of this flaw can lead to crashes of the httpd process or the device itself, resulting in a denial-of-service condition and loss of access to the web interface. Organizations using affected products should prioritize patching to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-9031
Severity
MEDIUM
CVSS
6.8
EPSS
0.16%

Original NVD Description

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. Successful exploitation may cause httpd process or device to crash, resulting in loss of access to the web interface and a denial-of-service condition.