CVE-2026-4195: D-Link DNS-1550-04 wizard_mgr.cgi command injection
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects an unknown function of the file /cgi-bin/wizardmgr.cgi. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4195?
CVE-2026-4195 is classified as a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-4195?
To fix CVE-2026-4195, update your affected D-Link device to the latest firmware version provided by D-Link.
Which devices are affected by CVE-2026-4195?
CVE-2026-4195 affects multiple D-Link devices including DNS-120, DNR-202L, DNS-315L, and several others up to version 20260205.
What kind of attack does CVE-2026-4195 enable?
CVE-2026-4195 allows unauthenticated users to execute arbitrary commands on the affected devices via crafted input.
Is there a workaround for CVE-2026-4195?
There are no official workarounds for CVE-2026-4195; updating to the latest firmware is the recommended solution.