CVE-2026-4209

EUVD-2026-12285
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function cgi_create_import_users/cgi_user_batch_create/cgi_user_set_quota/cgi_user_del/cgi_user_modify/cgi_group_set_quota/cgi_group_modify/cgi_group_add/cgi_user_add/cgi_get_modify_group_info/cgi_chg_admin_pw of the file /cgi-bin/account_mgr.cgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Injection
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dlinkdnr-202l_firmware
𝑥
≤ 2026-02-05
dlinkdnr-326_firmware
𝑥
≤ 2026-02-05
dlinkdns-1100-4_firmware
𝑥
≤ 2026-02-05
dlinkdns-120_firmware
𝑥
≤ 2026-02-05
dlinkdns-1200-05_firmware
𝑥
≤ 2026-02-05
dlinkdns-1550-04_firmware
𝑥
≤ 2026-02-05
dlinkdns-315l_firmware
𝑥
≤ 2026-02-05
dlinkdns-320_firmware
𝑥
≤ 2026-02-05
dlinkdns-320l_firmware
𝑥
≤ 2026-02-05
dlinkdns-320lw_firmware
𝑥
≤ 2026-02-05
dlinkdns-321_firmware
𝑥
≤ 2026-02-05
dlinkdns-322l_firmware
𝑥
≤ 2026-02-05
dlinkdns-323_firmware
𝑥
≤ 2026-02-05
dlinkdns-325_firmware
𝑥
≤ 2026-02-05
dlinkdns-326_firmware
𝑥
≤ 2026-02-05
dlinkdns-327l_firmware
𝑥
≤ 2026-02-05
dlinkdns-340l_firmware
𝑥
≤ 2026-02-05
dlinkdns-343_firmware
𝑥
≤ 2026-02-05
dlinkdns-345_firmware
𝑥
≤ 2026-02-05
dlinkdns-726-4_firmware
𝑥
≤ 2026-02-05
𝑥
= Vulnerable software versions