CVE-2026-4205: D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgirefreshdb/FTPServerBlockIPAdd/FTPServerBlockIPDel of the file /cgi-bin/appmgr.cgi. Such manipulation leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4205?
CVE-2026-4205 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-4205?
To fix CVE-2026-4205, users should update their affected D-Link devices to the latest firmware version available.
Which D-Link products are affected by CVE-2026-4205?
Affected D-Link products include the DNS-120, DNS-315L, DNS-320, DNS-323, DNS-340L, and several other models.
What type of attack can CVE-2026-4205 facilitate?
CVE-2026-4205 allows attackers to inject commands into the FTP server, potentially leading to unauthorized access.
Is there a workaround for CVE-2026-4205 if I cannot update immediately?
A temporary workaround is to disable the FTP server feature on the affected D-Link devices until a firmware update can be applied.