CVE-2026-4196: D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgirecovery/cgibackupnow/cgisetschedule/cgisetrsyncserver of the file /cgi-bin/remotebackup.cgi. The manipulation leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4196?
CVE-2026-4196 is considered a critical vulnerability due to its potential for remote command injection.
How do I fix CVE-2026-4196?
To fix CVE-2026-4196, update the firmware of your D-Link device to the latest version available after 20260205.
Which devices are affected by CVE-2026-4196?
CVE-2026-4196 affects multiple D-Link devices including DNS-120, DNS-320, DNS-340L, and others up to version 20260205.
What kind of attack can exploit CVE-2026-4196?
CVE-2026-4196 can be exploited through a command injection attack that can allow unauthorized remote access.
Is there a patch available for CVE-2026-4196?
Yes, a firmware update is available that addresses the vulnerabilities associated with CVE-2026-4196.