CVE-2026-4210: D-Link DNS-1550-04 time_machine.cgi cgi_tm_set_share command injection
A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function cgitmsetshare of the file /cgi-bin/timemachine.cgi. The manipulation of the argument Name results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4210?
CVE-2026-4210 is classified as a high severity vulnerability due to its potential to allow command injection.
How do I fix CVE-2026-4210?
To fix CVE-2026-4210, update affected D-Link devices to firmware version 20260205 or later.
Which devices are affected by CVE-2026-4210?
CVE-2026-4210 affects several D-Link devices including DNS-120, DNS-315L, DNS-320, and others up to version 20260205.
What is the impact of CVE-2026-4210?
The impact of CVE-2026-4210 allows attackers to execute arbitrary commands on the affected device, potentially compromising its security.
Have any exploits been reported for CVE-2026-4210?
As of now, specific public exploits for CVE-2026-4210 have not been disclosed.