CVE-2026-5211: D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflow
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnPAVServerPathDel of the file /cgi-bin/appmgr.cgi. Executing a manipulation of the argument fdir can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5211?
CVE-2026-5211 is classified as a stack-based buffer overflow vulnerability which can lead to remote code execution.
Which D-Link products are affected by CVE-2026-5211?
CVE-2026-5211 affects multiple D-Link products including DNS-120, DNS-320, and DNR-202L, among others.
How do I fix CVE-2026-5211?
To address CVE-2026-5211, update the affected devices to the latest firmware provided by D-Link.
What is the impact of exploiting CVE-2026-5211?
Exploitation of CVE-2026-5211 could allow an attacker to execute arbitrary code on the affected device.
Is there a workaround for CVE-2026-5211?
As a temporary solution for CVE-2026-5211, consider disabling UPnP on affected devices until a patch is applied.