CVE-2026-8260

HIGH

D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-8260. PoCs published by CryptReaper12.

AI-analyzed exploit summary The repository claims to exploit a buffer overflow in D-Link DCS-935L cameras via the HNAP service but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README provides minimal technical details and reads like a sales pitch.

Description

A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

Exploits (1)

nomisec SUSPICIOUS
by CryptReaper12 · poc
https://github.com/CryptReaper12/CVE-2026-8260

The repository claims to exploit a buffer overflow in D-Link DCS-935L cameras via the HNAP service but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README provides minimal technical details and reads like a sales pitch.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: D-Link DCS-935L firmware versions up to 1.10.01
No auth needed
Prerequisites: network access to the target device
devstral-2 · analyzed May 11, 2026 Full analysis →

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-362557 | D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
https://vuldb.com/vuln/362557
Signature, Permissions Required signature permissions-required
VDB-362557 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/362557/cti
Third Party Advisory third-party-advisory
Submit #809888 | D-Link DCS-935L ≤1.10.01 Buffer Overflow
https://vuldb.com/submit/809888
Product product
https://www.dlink.com/

Scores

CVSS v3 8.8
EPSS 0.0100
EPSS Percentile 58.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-120
Status published
Products (2)
D-Link/DCS-935L 1.10.01
dlink/dcs-935l_firmware < 1.10.01
Published May 11, 2026
Tracked Since May 11, 2026