CVE-2026-4194: D-Link DNS-1550-04 system_mgr.cgi cgi_set_wto access control
A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgisetwto of the file /cgi-bin/systemmgr.cgi. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4194?
CVE-2026-4194 is considered to have a high severity due to its potential impact on device security and access controls.
How do I fix CVE-2026-4194?
To fix CVE-2026-4194, you should update your affected D-Link device to the latest firmware version that addresses this vulnerability.
Which D-Link products are affected by CVE-2026-4194?
CVE-2026-4194 affects multiple D-Link products including DNS-120, DNR-202L, DNS-315L, DNS-320, and others.
What are the potential risks associated with CVE-2026-4194?
The risks associated with CVE-2026-4194 include unauthorized access to sensitive information and potential compromise of the device.
Is there a workaround for CVE-2026-4194 until a fix is applied?
While waiting for a fix for CVE-2026-4194, it is advisable to restrict access to the device and disable remote management features if possible.