CVE-2026-5214: D-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflow
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgiaddgroupgetgroupquotaminsize of the file /cgi-bin/accountmgr.cgi. The manipulation of the argument Name results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5214?
CVE-2026-5214 is classified as a moderate severity vulnerability due to its potential to cause a stack-based overflow.
How do I fix CVE-2026-5214?
To mitigate CVE-2026-5214, upgrade affected D-Link products to the latest firmware version available before 20260205.
Which D-Link products are affected by CVE-2026-5214?
CVE-2026-5214 affects various D-Link models including DNS-120, DNR-202L, DNS-315L, and several others listed in the advisory.
What kind of exploit is associated with CVE-2026-5214?
CVE-2026-5214 involves a stack-based overflow that could allow an attacker to gain unauthorized access to the system.
Is there a workaround for CVE-2026-5214 if I cannot update?
Currently, there are no known effective workarounds for CVE-2026-5214, making an update the best solution.