CVE-2026-4204: D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgimyfavoriteadd/cgimyfavoriteset/cgimyfavoritedel/cgimyfavoritesetsortinfo/cgimyfavoriteremoveapkg/cgimyfavoritecompareapkg/cgimycloudautodownlaod of the file /cgi-bin/guimgr.cgi. This manipulation of the argument fuser causes command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4204?
CVE-2026-4204 has been classified as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-4204?
To mitigate CVE-2026-4204, users should update their affected D-Link devices to the latest firmware version, ensuring vulnerabilities are patched.
Which D-Link devices are affected by CVE-2026-4204?
CVE-2026-4204 affects several D-Link models, including DNS-120, DNS-320LW, and DNR-202L, among others.
What type of vulnerability is CVE-2026-4204?
CVE-2026-4204 is identified as a command injection vulnerability within the D-Link devices' web management interface.
Can CVE-2026-4204 be exploited remotely?
Yes, CVE-2026-4204 can be exploited remotely if an attacker has access to the web management interface of the affected devices.