CVE-2026-8260
HIGHD-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
Title source: cnaDescription
A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Exploits (1)
References (5)
Core 5
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-362557 | D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
https://vuldb.com/vuln/362557
Signature, Permissions Required signature
permissions-required
VDB-362557 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/362557/cti
Third Party Advisory third-party-advisory
Submit #809888 | D-Link DCS-935L ≤1.10.01 Buffer Overflow
https://vuldb.com/submit/809888
Product product
https://www.dlink.com/
Scores
CVSS v3
8.8
EPSS
0.0004
EPSS Percentile
13.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-120
Status
published
Products (1)
D-Link/DCS-935L
1.10.01
Published
May 11, 2026
Tracked Since
May 11, 2026