Back

HIGH

devolo dLAN Cockpit 4.3.1 Unquoted Service Path Privilege Escalation

Published Jan 7, 2026

Description

devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows local non-privileged users to potentially execute arbitrary code. Attackers can exploit the insecure service path configuration by inserting malicious code in the system root path to execute with elevated privileges during application startup or system reboot.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 7, 2026
Updated Jan 8, 2026
Reserved Dec 17, 2025
CISA Vulnrichment
Updated Jan 8, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Jan 7, 2026
Updated Jan 8, 2026
Exploited since n/a
EUVD-2026-1615