CVE-2026-5213High· 8.8▾ TwilightA vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_adduser_to_session of the file /cgi-bin/account_mgr.cgi. This manipulation of the argument read_list causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
dnr-202l_firmware <= 2026-02-05dnr-326_firmware <= 2026-02-05dns-1100-4_firmware <= 2026-02-05dns-120_firmware <= 2026-02-05dns-1200-05_firmware <= 2026-02-05dns-1550-04_firmware <= 2026-02-05dns-315l_firmware <= 2026-02-05dns-320_firmware <= 2026-02-05dns-320l_firmware <= 2026-02-05dns-320lw_firmware <= 2026-02-05dns-321_firmware <= 2026-02-05dns-322l_firmware <= 2026-02-05dns-323_firmware <= 2026-02-05dns-325_firmware <= 2026-02-05dns-326_firmware <= 2026-02-05dns-327l_firmware <= 2026-02-05dns-340l_firmware <= 2026-02-05dns-343_firmware <= 2026-02-05dns-345_firmware <= 2026-02-05dns-726-4_firmware <= 2026-02-05Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-8260High· 8.8A vulnerability was found in D-Link DCS-935L up to 1.10.01
CVE-2026-5204High· 8.8A vulnerability was determined in Tenda CH22 1.0.0.1
CVE-2025-50671High· 7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /xwgl_ref.asp endpoint
CVE-2025-50664High· 7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint
CVE-2025-50663High· 7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
CVE-2025-50662High· 7.5A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.