CVE-2026-4209: D-Link DNS-1550-04 account_mgr.cgi cgi_chg_admin_pw command injection
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function cgicreateimportusers/cgiuserbatchcreate/cgiusersetquota/cgiuserdel/cgiusermodify/cgigroupsetquota/cgigroupmodify/cgigroupadd/cgiuseradd/cgigetmodifygroupinfo/cgichgadminpw of the file /cgi-bin/accountmgr.cgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4209?
CVE-2026-4209 has been rated as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-4209?
To remediate CVE-2026-4209, update the affected D-Link devices to the latest firmware version provided by D-Link.
Which devices are affected by CVE-2026-4209?
CVE-2026-4209 affects multiple D-Link models including DNS-120, DNS-320, DNR-202L, among others.
Can CVE-2026-4209 lead to unauthorized access?
Yes, CVE-2026-4209 can lead to unauthorized access through command injection, allowing attackers to execute arbitrary commands.
What is the impact of exploiting CVE-2026-4209?
Exploiting CVE-2026-4209 can result in complete control over the affected device, leading to potential data breaches.