CVE-2026-5213
D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_adduser_to_session of the file /cgi-bin/account_mgr.cgi. This manipulation of the argument read_list causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DNR-202LD-Link · DNR-322LD-Link · DNR-326D-Link · DNS-1100-4D-Link · DNS-120D-Link · DNS-1200-05D-Link · DNS-1550-04D-Link · DNS-315LD-Link · DNS-320D-Link · DNS-320LD-Link · DNS-320LWD-Link · DNS-321D-Link · DNS-323D-Link · DNS-325D-Link · DNS-326D-Link · DNS-327LD-Link · DNS-340LD-Link · DNS-343D-Link · DNS-345D-Link · DNS-726-4public PoCs found — 1
cve_referencegithub.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_168/168.mdunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →