CVE-2026-4529Disclosure(dlink / dhp-1320)

HIGHCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Prioritize remediation for dlink dhp-1320 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

7.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-119CWE-121

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dhp-1320
  • dhp-1320_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-03-22); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
dhp-1320dhp-1320_firmware

2 versions affected across 2 products

Deep dive

Activity timeline9 mentions / 3d
01345Mentions · 2026-03-21: 3Mentions · 2026-03-22: 5Mentions · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-22: 1Exploit Tool / Code · 2026-03-22: 1Active Exploitation · 2026-03-22: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-22: 2Technical Details · 2026-03-27: 103-2103-2203-27
Signal classification4 categories
Disclosure
555.6%
General
222.2%
Active Exploitation
111.1%
Exploit
111.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-213
Disclosure3
2026-03-225
Active Exploitation1Disclosure2Exploit1General1
2026-03-271
General1
Full discourse9 posts
  • IntegSec@integ_sec
    General

    CVE-2026-4529: D-Link DHP-1320 SOAP Handler Buffer Overflow - What It Means for Your Business and How to Respond https://hubs.li/Q048CTNk0

    Post summary

    The text identifies CVE-2026-4529 as a buffer overflow in a D‑Link DHP‑1320 SOAP handler but offers no evidence of PoC, exploitation, or mitigation details.

    0000032
    31 followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DHP-1320 SOAP redirect_count_down_page stack-based overflow CVE: CVE-2026-4529 PT-Identifier: PT-2026-26918 Vendor: D-link Product: DHP-1320 CVSS: 8.7 Credits: xiaobor123 (VulDB User) Description: A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4529 • https://vuldb.com/?id.352317 • https://vuldb.com/?ctiid.352317 • https://vuldb.com/?submit.773932 • https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dhp1320-dlink • https://www.dlink.com/ #dbugs_vuln

    Post summary

    CVE-2026-4529 is a stack-based buffer overflow in D-Link DHP-1320 with a publicly available exploit (GitHub), but no evidence of active exploitation or available patch.

    0000077
    697 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting D-Link DHP-1320 (CVE-2026-4529) https://vuldb.com/?ctiid.352317

    Post summary

    Elevated activity targeting D-Link DHP‑1320 with CVE-2026-4529 suggests potential active exploitation, but no PoC, exploit code, patch, or detailed technical information is provided.

    0000051
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4529 A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads t… https://www.cve.org/CVERecord?id=CVE-2026-4529

    Post summary

    The text announces the discovery of CVE-2026-4529 in a D-Link device, describing the affected component but providing no PoC, exploitation details, or mitigation information.

    0000067
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4529 - D-Link - DHP-1320 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4529-d-link-dhp-1320/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4529 #d-link #dhp-1320

    Post summary

    The tweet merely announces CVE‑2026‑4529 and shares a link, but provides no specific technical details, exploit code, or evidence of active exploitation.

    0000072
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4529 - D-Link DHP-1320 SOAP redirect_count_down_page stack-based overflow Intel Report: https://ift.tt/qXKna9V

    Post summary

    The alert announces CVE-2026-4529, a stack‑based overflow in D-Link DHP‑1320’s SOAP redirect_count_down_page, and provides a link to an Intel report for further information.

    0000028
    291 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4529 - High A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer ove... https://www.thehackerwire.com/vulnerability/CVE-2026-4529/ https://t.co/Pi2vGd2KhE

    Post summary

    The text announces CVE-2026-4529, a high‑severity stack‑based buffer overflow in the redirect_count_down_page function of D‑Link DHP‑1320's SOAP Handler. No PoC, exploit, or patch information is provided.

    0000027
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4529: HIGH] Critical cyber security alert: Vulnerability discovered in D-Link DHP-1320 1.00WWB04 SOAP Handler could lead to a remote stack-based buffer overflow attack. Limited to unsupported products.#cve,CVE-2026-4529,#cybersecurity https://cvefind.com/CVE-2026-4529

    Post summary

    The tweet announces a high‑severity, stack‑based buffer overflow vulnerability (CVE‑2026‑4529) in the D‑Link DHP‑1320 SOAP handler and highlights its potential for remote exploitation, but provides no PoC, exploit code, patch, or indication of active attacks.

    0000064
    604 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for D-Link DHP-1320 (CVE-2026-4529) https://vuldb.com/?id.352317

    Post summary

    A new vulnerability, CVE-2026-4529, was disclosed for the D-Link DHP-1320 router and is reported to have an increased severity.

    0000058
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdhp-1320a1--
OSdlinkdhp-1320_firmware1.00wwb04--

Explore more