CVE-2026-5212Disclosure(dlink / dnr-202l)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch dlink dnr-202l systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function Webdav_Upload_File of the file /cgi-bin/webdav_mgr.cgi. The manipulation of the argument f_file leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnr-202l
  • dnr-202l_firmware
  • dnr-326
  • dnr-326_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-04-01)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dnr-202ldnr-202l_firmwarednr-326dnr-326_firmwaredns-1100-4dns-1100-4_firmwaredns-120dns-1200-05dns-1200-05_firmwaredns-120_firmware

1 version affected across 40 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-31: 1Mentions · 2026-04-01: 4PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-3104-01
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-014
Disclosure3General1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5212 A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS… https://www.cve.org/CVERecord?id=CVE-2026-5212

    Post summary

    The text announces that CVE‑2026‑5212 has been found in multiple D‑Link router models and directs readers to the CVE.org record for further information.

    00010148
    56.9K followersView on X
  • dbugs@ptdbugs
    Disclosure

    D-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow CVE: CVE-2026-5212 PT-Identifier: PT-2026-29347 Vendor: D-link Product: DNS-120 CVSS: 8.7 Credits: Ziyue Xie (VulDB User) Description: A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function Webdav_Upload_File of the file /cgi-bin/webdav_mgr.cgi. The manipulation of the argument f_file leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5212 • https://vuldb.com/vuln/354348 • https://vuldb.com/vuln/354348/cti • https://vuldb.com/submit/780435 • https://vuldb.com/submit/780436 • https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_166/166.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The post announces a publicly disclosed stack-based buffer overflow in D-Link DNS products with detailed technical specifics but lacks evidence of active exploitation or mitigation information.

    00001138
    781 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5212 A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS… https://www.cve.org/CVERecord?id=CVE-2026-5212 ----- Traducción: CVE-2026-5212 Se … http://infoflow.cloud`

    Post summary

    The text announces the discovery of CVE-2026-5212 in a range of D-Link devices but provides no substantive technical data, exploitation details, or remediation guidance.

    0000020
    65 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5212 - High A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345,... https://www.thehackerwire.com/vulnerability/CVE-2026-5212/ https://t.co/PMDybDKTHn

    Post summary

    The tweet announces a new high‑severity vulnerability (CVE‑2026‑5212) affecting several D‑Link router models, but provides only a list of affected devices without further technical or exploit details.

    0000039
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-5212: HIGH] Vulnerability discovered in D-Link NAS devices. Exploit allows remote stack-based buffer overflow through Webdav_Upload_File function. Users urged to update devices to latest firmware.#cve,CVE-2026-5212,#cybersecurity https://cvefind.com/CVE-2026-5212

    Post summary

    The post discloses a stack‑based buffer overflow in D-Link NAS devices and urges users to apply the latest firmware to mitigate the vulnerability.

    0000050
    617 followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdnr-202l---
OSdlinkdnr-202l_firmware---
HWdlinkdnr-326---
OSdlinkdnr-326_firmware---
HWdlinkdns-1100-4---
OSdlinkdns-1100-4_firmware---
HWdlinkdns-120---
HWdlinkdns-1200-05---
OSdlinkdns-1200-05_firmware---
OSdlinkdns-120_firmware---
HWdlinkdns-1550-04---
OSdlinkdns-1550-04_firmware---
HWdlinkdns-315l---
OSdlinkdns-315l_firmware---
HWdlinkdns-320---
OSdlinkdns-320_firmware---
HWdlinkdns-320l---
OSdlinkdns-320l_firmware---
HWdlinkdns-320lw---
OSdlinkdns-320lw_firmware---
HWdlinkdns-321---
OSdlinkdns-321_firmware---
HWdlinkdns-322l---
OSdlinkdns-322l_firmware---
HWdlinkdns-323---
OSdlinkdns-323_firmware---
HWdlinkdns-325---
OSdlinkdns-325_firmware---
HWdlinkdns-326---
OSdlinkdns-326_firmware---
HWdlinkdns-327l---
OSdlinkdns-327l_firmware---
HWdlinkdns-340l---
OSdlinkdns-340l_firmware---
HWdlinkdns-343---
OSdlinkdns-343_firmware---
HWdlinkdns-345---
OSdlinkdns-345_firmware---
HWdlinkdns-726-4---
OSdlinkdns-726-4_firmware---

Explore more