CVE-2026-4211: D-Link DNS-1550-04 local_backup_mgr.cgi Local_Backup_Info stack-based overflow
A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this issue is the function LocalBackupInfo of the file /cgi-bin/localbackupmgr.cgi. This manipulation of the argument fidx causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4211?
The severity of CVE-2026-4211 is high due to its potential for stack-based buffer overflow, which can lead to arbitrary code execution.
How do I fix CVE-2026-4211?
To fix CVE-2026-4211, update your affected D-Link device to the latest firmware version provided by D-Link.
Which devices are affected by CVE-2026-4211?
Devices affected by CVE-2026-4211 include various models such as D-Link DNS-120, DNS-320, DNS-340L, and others listed in the vulnerability report.
What type of vulnerability is CVE-2026-4211?
CVE-2026-4211 is a stack-based buffer overflow vulnerability affecting specific D-Link network devices.
Is there a workaround for CVE-2026-4211 until a patch is available?
Currently, the best workaround for CVE-2026-4211 is to limit access to the affected D-Link devices or disable the affected services.