CVE-2026-4214General(dlink / dnr-202l)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnP_AV_Server_Path_Setting of the file /cgi-bin/app_mgr.cgi. Executing a manipulation can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnr-202l
  • dnr-202l_firmware
  • dnr-326
  • dnr-326_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Exploit: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-16); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
dnr-202ldnr-202l_firmwarednr-326dnr-326_firmwaredns-1100-4dns-1100-4_firmwaredns-120dns-1200-05dns-1200-05_firmwaredns-120_firmware

1 version affected across 40 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-15: 1Mentions · 2026-03-16: 3Mentions · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-16: 1Technical Details · 2026-03-16: 203-1503-1603-17
Signal classification3 categories
General
240.0%
Exploit
240.0%
Disclosure
120.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-151
General1
2026-03-163
Disclosure1Exploit2
2026-03-171
General1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-4214 A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DN… https://www.cve.org/CVERecord?id=CVE-2026-4214

    Post summary

    A vulnerability (CVE-2026-4214) was identified in several D-Link router models; the provided snippet only lists affected devices without details on exploitation, patches, or technical specifics.

    00000145
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4214: HIGH] Critical flaw in multiple D-Link models (DNS- & DNR-)! Vulnerability in UPnP_AV_Server_Path_Setting function allows remote buffer overflow attacks. Exploit available!#cve,CVE-2026-4214,#cybersecurity https://cvefind.com/CVE-2026-4214

    Post summary

    The tweet announces a critical buffer‑overflow flaw in D‑Link's UPnP servers, noting that an exploit exists but providing no code or evidence of live attacks.

    0000053
    601 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4214 - High A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-... https://www.thehackerwire.com/vulnerability/CVE-2026-4214/ https://t.co/nNj6jVg88q

    Post summary

    The tweet announces the discovery of CVE‑2026‑4214, a high‑severity vulnerability affecting a range of D‑Link routers, and points to an external article for more information.

    0000045
    136 followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Setting stack-based overflow CVE: CVE-2026-4214 PT-Identifier: PT-2026-25566 Vendor: D-link Product: DNS-120 CVSS: 8.7 Credits: pjq123 (VulDB User) Description: A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function UPnP_AV_Server_Path_Setting of the file /cgi-bin/app_mgr.cgi. Executing a manipulation can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4214 • https://vuldb.com/?id.351125 • https://vuldb.com/?ctiid.351125 • https://vuldb.com/?submit.770445 • https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_164/164.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    Researchers disclosed a stack‑based buffer overflow in D‑Link DNS‑120 series firmware (CVE‑2026‑4214), noting that a published exploit exists and could be employed remotely, yet no active exploitation evidence or patch information is provided.

    0000094
    612 followersView on X
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting D-Link DNS-120 and other products (CVE-2026-4214) https://vuldb.com/?id.351125

    Post summary

    A new vulnerability (CVE-2026-4214) affecting D-Link DNS-120 and other products has been reported, but no further details, exploitation evidence, or remediation information are provided.

    0000083
    2.1K followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdnr-202l---
OSdlinkdnr-202l_firmware---
HWdlinkdnr-326---
OSdlinkdnr-326_firmware---
HWdlinkdns-1100-4---
OSdlinkdns-1100-4_firmware---
HWdlinkdns-120---
HWdlinkdns-1200-05---
OSdlinkdns-1200-05_firmware---
OSdlinkdns-120_firmware---
HWdlinkdns-1550-04---
OSdlinkdns-1550-04_firmware---
HWdlinkdns-315l---
OSdlinkdns-315l_firmware---
HWdlinkdns-320---
OSdlinkdns-320_firmware---
HWdlinkdns-320l---
OSdlinkdns-320l_firmware---
HWdlinkdns-320lw---
OSdlinkdns-320lw_firmware---
HWdlinkdns-321---
OSdlinkdns-321_firmware---
HWdlinkdns-322l---
OSdlinkdns-322l_firmware---
HWdlinkdns-323---
OSdlinkdns-323_firmware---
HWdlinkdns-325---
OSdlinkdns-325_firmware---
HWdlinkdns-326---
OSdlinkdns-326_firmware---
HWdlinkdns-327l---
OSdlinkdns-327l_firmware---
HWdlinkdns-340l---
OSdlinkdns-340l_firmware---
HWdlinkdns-343---
OSdlinkdns-343_firmware---
HWdlinkdns-345---
OSdlinkdns-345_firmware---
HWdlinkdns-726-4---
OSdlinkdns-726-4_firmware---

Explore more