CVE-2026-4203: D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection
A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgiportforwardingadd/cgiportforwardingdel/cgiportforwardingmodify/cgiportforwardingaddscan/cgidhcpdlease/cgiddns/cgiip/cgidhcpd of the file /cgi-bin/networkmgr.cgi. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4203?
CVE-2026-4203 has a high severity rating due to potential command injection vulnerabilities.
How do I fix CVE-2026-4203?
To fix CVE-2026-4203, update your D-Link devices to the latest firmware version available as of February 2026.
Which D-Link models are affected by CVE-2026-4203?
CVE-2026-4203 affects various D-Link models including DNS-120, DNS-1550-04, and several others up to version 20260205.
What actions can be taken to mitigate the risks of CVE-2026-4203?
Mitigation steps for CVE-2026-4203 include disabling unnecessary features and changing default passwords on affected D-Link devices.
Is CVE-2026-4203 actively being exploited in the wild?
As of now, there is no confirmed evidence that CVE-2026-4203 is being actively exploited, but immediate remediation is recommended.