CVE-2026-5213: D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgiaddusertosession of the file /cgi-bin/accountmgr.cgi. This manipulation of the argument readlist causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5213?
CVE-2026-5213 is classified as a high severity vulnerability due to the potential for a stack-based overflow that can be exploited by attackers.
How do I fix CVE-2026-5213?
To fix CVE-2026-5213, update the affected D-Link devices to the latest firmware version that addresses this vulnerability.
Which D-Link devices are impacted by CVE-2026-5213?
CVE-2026-5213 affects several D-Link devices, including DNS-120, DNS-320, DNS-340L, and others up to version 20260205.
What kind of attack can exploit CVE-2026-5213?
CVE-2026-5213 can be exploited through a stack-based buffer overflow, potentially allowing remote code execution.
Is there a workaround for CVE-2026-5213 while waiting for a fix?
Currently, there are no approved workarounds for CVE-2026-5213, so updating the firmware is the recommended action.