CVE-2026-8260
HIGHD-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-8260. PoCs published by CryptReaper12.
AI-analyzed exploit summary The repository claims to exploit a buffer overflow in D-Link DCS-935L cameras via the HNAP service but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README provides minimal technical details and reads like a sales pitch.
Description
A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Exploits (1)
The repository claims to exploit a buffer overflow in D-Link DCS-935L cameras via the HNAP service but lacks actual exploit code, instead redirecting users to an external download link (tinyurl). The README provides minimal technical details and reads like a sales pitch.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H