CVE-2026-4211
HIGHD-Link DNS-1550-04 local_backup_mgr.cgi Local_Backup_Info stack-based overflow
Title source: cnaDescription
A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this issue is the function Local_Backup_Info of the file /cgi-bin/local_backup_mgr.cgi. This manipulation of the argument f_idx causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Scores
CVSS v3
8.8
EPSS
0.0006
EPSS Percentile
18.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
CWE-119
CWE-121
Status
published
Products (40)
D-Link/DNR-202L
20260205
D-Link/DNR-322L
20260205
D-Link/DNR-326
20260205
D-Link/DNS-1100-4
20260205
D-Link/DNS-120
20260205
D-Link/DNS-1200-05
20260205
D-Link/DNS-1550-04
20260205
D-Link/DNS-315L
20260205
D-Link/DNS-320
20260205
D-Link/DNS-320L
20260205
... and 30 more
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026