CVE-2026-4214: D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Setting stack-based overflow
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnPAVServerPathSetting of the file /cgi-bin/appmgr.cgi. Executing a manipulation can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4214?
CVE-2026-4214 is classified as a critical vulnerability due to the stack-based buffer overflow it introduces.
How do I fix CVE-2026-4214?
To fix CVE-2026-4214, users should update their affected D-Link devices to the latest firmware version available.
Which devices are affected by CVE-2026-4214?
CVE-2026-4214 affects multiple D-Link NAS devices including the DNS-120, DNS-320, DNR-202L, and others listed in the vulnerability report.
What kind of attack can exploit CVE-2026-4214?
CVE-2026-4214 can be exploited by attackers to execute arbitrary code or cause a denial-of-service condition on affected devices.
Is there a way to mitigate CVE-2026-4214 if I can't immediately update?
If an immediate update is not possible, users should disable UPnP features on affected devices to mitigate the risk associated with CVE-2026-4214.