CVE-2026-4211Disclosure(dlink / dnr-202l)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dnr-202l systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this issue is the function Local_Backup_Info of the file /cgi-bin/local_backup_mgr.cgi. This manipulation of the argument f_idx causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnr-202l
  • dnr-202l_firmware
  • dnr-326
  • dnr-326_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-16); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dnr-202ldnr-202l_firmwarednr-326dnr-326_firmwaredns-1100-4dns-1100-4_firmwaredns-120dns-1200-05dns-1200-05_firmwaredns-120_firmware

1 version affected across 40 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-16: 4Mentions · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-03-16: 1Technical Details · 2026-03-16: 303-1603-17
Signal classification2 categories
Disclosure
480.0%
Exploit
120.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-164
Disclosure3Exploit1
2026-03-171
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4211 A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS… https://www.cve.org/CVERecord?id=CVE-2026-4211

    Post summary

    A weakness has been identified for multiple D-Link DNS router models, referenced by CVE-2026-4211.

    00000151
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4211: HIGH] Critical security flaw found in multiple D-Link models, allowing remote attackers to trigger a stack-based buffer overflow via the Local_Backup_Info function in /cgi-bin/local_backup_mgr....#cve,CVE-2026-4211,#cybersecurity https://cvefind.com/CVE-2026-4211

    Post summary

    The post announces a HIGH‑severity stack‑based buffer overflow in multiple D-Link models’ Local_Backup_Info function (CVE-2026-4211), providing only technical details without any PoC, exploit, patch, or active exploitation evidence.

    0000039
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4211 - High A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345,... https://www.thehackerwire.com/vulnerability/CVE-2026-4211/ https://t.co/O2oasATE6N

    Post summary

    The tweet announces CVE‑2026‑4211, a high‑severity weakness affecting multiple D‑Link DNS models, and provides a link to a vulnerability report.

    0000037
    136 followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DNS-1550-04 local_backup_mgr.cgi Local_Backup_Info stack-based overflow CVE: CVE-2026-4211 Vendor: D-link Product: DNS-120 CVSS: 8.7 Credits: pjqwudi (VulDB User) Description: A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this issue is the function Local_Backup_Info of the file /cgi-bin/local_backup_mgr.cgi. This manipulation of the argument f_idx causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4211 • https://vuldb.com/?id.351122 • https://vuldb.com/?ctiid.351122 • https://vuldb.com/?submit.770441 • https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_160/160.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    This post announces a stack-based buffer overflow in D-Link DNS devices, confirms a public exploit exists on GitHub, but provides no evidence of active exploitation or patches.

    0000077
    612 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4211 - D-Link DNS-1550-04 local_backup_mgr.cgi Local_Backup_Info stack-based overflow Intel Report: https://ift.tt/mk4L2y9

    Post summary

    The post announces CVE-2026-4211, a stack‑based overflow in D-Link DNS‑1550‑04, and links to an Intel Report, but does not provide PoC, exploit details, or patch information.

    0000046
    335 followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdnr-202l---
OSdlinkdnr-202l_firmware---
HWdlinkdnr-326---
OSdlinkdnr-326_firmware---
HWdlinkdns-1100-4---
OSdlinkdns-1100-4_firmware---
HWdlinkdns-120---
HWdlinkdns-1200-05---
OSdlinkdns-1200-05_firmware---
OSdlinkdns-120_firmware---
HWdlinkdns-1550-04---
OSdlinkdns-1550-04_firmware---
HWdlinkdns-315l---
OSdlinkdns-315l_firmware---
HWdlinkdns-320---
OSdlinkdns-320_firmware---
HWdlinkdns-320l---
OSdlinkdns-320l_firmware---
HWdlinkdns-320lw---
OSdlinkdns-320lw_firmware---
HWdlinkdns-321---
OSdlinkdns-321_firmware---
HWdlinkdns-322l---
OSdlinkdns-322l_firmware---
HWdlinkdns-323---
OSdlinkdns-323_firmware---
HWdlinkdns-325---
OSdlinkdns-325_firmware---
HWdlinkdns-326---
OSdlinkdns-326_firmware---
HWdlinkdns-327l---
OSdlinkdns-327l_firmware---
HWdlinkdns-340l---
OSdlinkdns-340l_firmware---
HWdlinkdns-343---
OSdlinkdns-343_firmware---
HWdlinkdns-345---
OSdlinkdns-345_firmware---
HWdlinkdns-726-4---
OSdlinkdns-726-4_firmware---

Explore more