CVE-2026-5211Disclosure(dlink / dnr-202l)

MEDIUMCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch dlink dnr-202l systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnP_AV_Server_Path_Del of the file /cgi-bin/app_mgr.cgi. Executing a manipulation of the argument f_dir can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnr-202l
  • dnr-202l_firmware
  • dnr-326
  • dnr-326_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 6 mentions (2026-04-01); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
dnr-202ldnr-202l_firmwarednr-326dnr-326_firmwaredns-1100-4dns-1100-4_firmwaredns-120dns-1200-05dns-1200-05_firmwaredns-120_firmware

1 version affected across 40 products

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-03-31: 1Mentions · 2026-04-01: 6Mentions · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-09: 103-3104-0104-09
Signal classification3 categories
Disclosure
675.0%
Exploit
112.5%
General
112.5%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-016
Disclosure4Exploit1General1
2026-04-091
Disclosure1
Full discourse8 posts
  • Tolga İlhan@ilhntolga
    Disclosure

    d-link yine güvenlik skandalı. 15 farklı nas ve nvr cihazında yüksek şiddetli uzaktan istismar edilebilir buffer overflow açığı bulunmuş — cve-2026-5211. upnp_av_server_path_del fonksiyonundaki stack taşması, saldırgana uzaktan kod çalıştırma imkanı veriyor. shodan'da binlerce etkilenen cihaz internete bağlı durumda. peki kim güncelleyecek bu cihazları? d-link'in eski ürünlere yama desteği vermeyi bıraktığı malum. dns-323, dns-325 gibi modeller 2010'lardan kalma , üretici çoktan tarihin tozlu raflarına kaldırmış bunları.ihazların çoğu için güncelleme gelmeyecek. ya altyapınızdaki d-link'i bulup değiştireceksiniz ya da kabul edeceksiniz ki iç ağınızda potansiyel bir giriş noktası var. bu d-link için yeni değil aslında. yıllardır benzer açıklar, yıllardır benzer uyarılar. smb-USB-nas üçgeninde ucuz çözüm arayanların cehennemi.

    Post summary

    D‑Link devices suffer a high‑severity buffer overflow (CVE‑2026‑5211) that allows remote code execution; thousands are exposed via Shodan, but no patches or exploit code are offered.

    1000048
    714 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5211 A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DN… https://www.cve.org/CVERecord?id=CVE-2026-5211

    Post summary

    The post announces a CVE affecting several D-Link router models without offering further technical, exploitation, or remediation details.

    01000257
    56.9K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-5211: D-Link NAS Stack Buffer Overflow - What It Means for Your Business and How to Respond https://hubs.li/Q04b9Bft0

    Post summary

    The headline announces CVE‑2026‑5211, a stack buffer overflow in D‑Link NAS devices, and promises guidance on business impact and response steps.

    0000031
    28 followersView on X
  • Tolga İlhan@ilhntolga
    General

    kaynaklar: https://www.cve.org/CVERecord?id=CVE-2026-5211

    Post summary

    The text merely references a CVE record via a link, with no additional details about the vulnerability or its exploitation.

    0000031
    716 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5211 A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DN… https://www.cve.org/CVERecord?id=CVE-2026-5211 ----- Traducción: CVE-2026-5211 Se … http://infoflow.cloud`

    Post summary

    The tweet announces a newly identified flaw (CVE-2026-5211) affecting several D-Link router models, providing minimal technical or remediation details.

    0000023
    65 followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflow CVE: CVE-2026-5211 Vendor: D-link Product: DNS-120 CVSS: 8.7 Credits: Ziyue Xie (VulDB User) Description: A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnP_AV_Server_Path_Del of the file /cgi-bin/app_mgr.cgi. Executing a manipulation of the argument f_dir can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5211 • https://vuldb.com/vuln/354347 • https://vuldb.com/vuln/354347/cti • https://vuldb.com/submit/780434 • https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_165/165.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The text discloses a stack‑based buffer overflow in multiple D‑Link router models (CVE‑2026‑5211), confirms that an exploit has been published and provides code references, but does not report active exploitation or patch information.

    00000135
    781 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5211 - High A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-... https://www.thehackerwire.com/vulnerability/CVE-2026-5211/ https://t.co/jYEQWgAIca

    Post summary

    A new CVE‑2026‑5211 vulnerability affecting many D‑Link devices is announced, with no details on exploitation, patching, or the vulnerability’s technical nature.

    0000058
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5211: HIGH] Critical vulnerability in multiple D-Link devices can lead to remote stack-based buffer overflow. Attackers can exploit flaw in UPnP server. Patch recommended.#cve,CVE-2026-5211,#cybersecurity https://cvefind.com/CVE-2026-5211

    Post summary

    The tweet announces a high‑severity stack‑based buffer overflow in D‑Link UPnP servers (CVE‑2026‑5211), notes that a patch is recommended, but provides no PoC, exploit code, or evidence of active exploitation.

    0000039
    617 followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdnr-202l---
OSdlinkdnr-202l_firmware---
HWdlinkdnr-326---
OSdlinkdnr-326_firmware---
HWdlinkdns-1100-4---
OSdlinkdns-1100-4_firmware---
HWdlinkdns-120---
HWdlinkdns-1200-05---
OSdlinkdns-1200-05_firmware---
OSdlinkdns-120_firmware---
HWdlinkdns-1550-04---
OSdlinkdns-1550-04_firmware---
HWdlinkdns-315l---
OSdlinkdns-315l_firmware---
HWdlinkdns-320---
OSdlinkdns-320_firmware---
HWdlinkdns-320l---
OSdlinkdns-320l_firmware---
HWdlinkdns-320lw---
OSdlinkdns-320lw_firmware---
HWdlinkdns-321---
OSdlinkdns-321_firmware---
HWdlinkdns-322l---
OSdlinkdns-322l_firmware---
HWdlinkdns-323---
OSdlinkdns-323_firmware---
HWdlinkdns-325---
OSdlinkdns-325_firmware---
HWdlinkdns-326---
OSdlinkdns-326_firmware---
HWdlinkdns-327l---
OSdlinkdns-327l_firmware---
HWdlinkdns-340l---
OSdlinkdns-340l_firmware---
HWdlinkdns-343---
OSdlinkdns-343_firmware---
HWdlinkdns-345---
OSdlinkdns-345_firmware---
HWdlinkdns-726-4---
OSdlinkdns-726-4_firmware---

Explore more