CVE-2026-4196

EUVD-2026-12264
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgi_recovery/cgi_backup_now/cgi_set_schedule/cgi_set_rsync_server of the file /cgi-bin/remote_backup.cgi. The manipulation leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Injection
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dlinkdns-1550-04_firmware
𝑥
≤ 2026-02-05
dlinkdns-315l_firmware
𝑥
≤ 2026-02-05
dlinkdns-320_firmware
𝑥
≤ 2026-02-05
dlinkdns-320l_firmware
𝑥
≤ 2026-02-05
dlinkdns-320lw_firmware
𝑥
≤ 2026-02-05
dlinkdns-321_firmware
𝑥
≤ 2026-02-05
dlinkdns-322l_firmware
𝑥
≤ 2026-02-05
dlinkdns-323_firmware
𝑥
≤ 2026-02-05
dlinkdns-325_firmware
𝑥
≤ 2026-02-05
dlinkdns-326_firmware
𝑥
≤ 2026-02-05
dlinkdns-327l_firmware
𝑥
≤ 2026-02-05
dlinkdns-340l_firmware
𝑥
≤ 2026-02-05
dlinkdns-343_firmware
𝑥
≤ 2026-02-05
dlinkdns-345_firmware
𝑥
≤ 2026-02-05
dlinkdns-726-4_firmware
𝑥
≤ 2026-02-05
dlinkdnr-202l_firmware
𝑥
≤ 2026-02-05
dlinkdnr-326_firmware
𝑥
≤ 2026-02-05
dlinkdns-1100-4_firmware
𝑥
≤ 2026-02-05
dlinkdns-120_firmware
𝑥
≤ 2026-02-05
dlinkdns-1200-05_firmware
𝑥
≤ 2026-02-05
𝑥
= Vulnerable software versions