CVE-2026-4206: D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This affects the function FMTrebuilddiskmgr/FMTcreatediskmgr/ScanDiskrune2fsck of the file /cgi-bin/dskmgr.cgi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4206?
CVE-2026-4206 is considered a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-4206?
To fix CVE-2026-4206, update your affected D-Link devices to the latest firmware version provided by D-Link.
What devices are affected by CVE-2026-4206?
CVE-2026-4206 affects several D-Link devices including DNS-120, DNS-320, and DNS-340L among others.
What is the impact of CVE-2026-4206?
The impact of CVE-2026-4206 allows an attacker to execute arbitrary commands on vulnerable devices, compromising their integrity.
When was CVE-2026-4206 discovered?
CVE-2026-4206 was reported recently, highlighting an ongoing security concern for users of affected D-Link products.