CVE-2026-5212: D-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function WebdavUploadFile of the file /cgi-bin/webdavmgr.cgi. The manipulation of the argument ffile leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5212?
CVE-2026-5212 is classified as a stack-based buffer overflow vulnerability.
How do I fix CVE-2026-5212?
To mitigate CVE-2026-5212, upgrade the affected D-Link devices to the latest firmware version 20260205.
Which D-Link products are affected by CVE-2026-5212?
CVE-2026-5212 affects various D-Link models including DNS-120, DNR-202L, and DNS-1550-04 among others.
What could happen if CVE-2026-5212 is exploited?
Exploitation of CVE-2026-5212 could allow an attacker to execute arbitrary code on the affected devices.
Is there any public exploit for CVE-2026-5212?
As of now, there are no known public exploits available for CVE-2026-5212.