HarborGuard / CVE
Back to search
HIGHCVE-2026-5212Published Modified CNA VulDB

CVE-2026-5212: D-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function Webdav_Upload_File of the file /cgi-bin/webdav_mgr.cgi. The manipulation of the argument f_file leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
Affected Products
20
Affected packages
  • D-Link / DNS-120
    20260205
  • D-Link / DNR-202L
    20260205
  • D-Link / DNS-315L
    20260205
  • D-Link / DNS-320
    20260205
  • D-Link / DNS-320L
    20260205
  • D-Link / DNS-320LW
    20260205
  • D-Link / DNS-321
    20260205
  • D-Link / DNR-322L
    20260205
  • D-Link / DNS-323
    20260205
  • D-Link / DNS-325
    20260205
  • D-Link / DNS-326
    20260205
  • D-Link / DNS-327L
    20260205
  • D-Link / DNR-326
    20260205
  • D-Link / DNS-340L
    20260205
  • D-Link / DNS-343
    20260205
  • D-Link / DNS-345
    20260205
  • D-Link / DNS-726-4
    20260205
  • D-Link / DNS-1100-4
    20260205
  • D-Link / DNS-1200-05
    20260205
  • D-Link / DNS-1550-04
    20260205
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P